Логотип exploitDog
bind:CVE-2019-17573
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-17573

Количество 4

Количество 4

redhat логотип

CVE-2019-17573

около 6 лет назад

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVSS3: 6.1
EPSS: Средний
nvd логотип

CVE-2019-17573

около 6 лет назад

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-f93p-f762-vr53

больше 5 лет назад

Reflected Cross-Site Scripting in Apache CXF

CVSS3: 6.1
EPSS: Средний
fstec логотип

BDU:2020-04512

около 6 лет назад

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществить межсайтовую сценарную атаку

CVSS3: 6.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-17573

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVSS3: 6.1
16%
Средний
около 6 лет назад
nvd логотип
CVE-2019-17573

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVSS3: 6.1
16%
Средний
около 6 лет назад
github логотип
GHSA-f93p-f762-vr53

Reflected Cross-Site Scripting in Apache CXF

CVSS3: 6.1
16%
Средний
больше 5 лет назад
fstec логотип
BDU:2020-04512

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществить межсайтовую сценарную атаку

CVSS3: 6.1
16%
Средний
около 6 лет назад

Уязвимостей на страницу