4.3
CVE-2013-4378
- EPSS 1%
- Veröffentlicht 30.09.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emeric Vernat ≫ Javamelody Version <= 1.46
Emeric Vernat ≫ Javamelody Version1.6
Emeric Vernat ≫ Javamelody Version1.7
Emeric Vernat ≫ Javamelody Version1.8
Emeric Vernat ≫ Javamelody Version1.9
Emeric Vernat ≫ Javamelody Version1.10
Emeric Vernat ≫ Javamelody Version1.11
Emeric Vernat ≫ Javamelody Version1.12
Emeric Vernat ≫ Javamelody Version1.13
Emeric Vernat ≫ Javamelody Version1.14
Emeric Vernat ≫ Javamelody Version1.15
Emeric Vernat ≫ Javamelody Version1.16
Emeric Vernat ≫ Javamelody Version1.17
Emeric Vernat ≫ Javamelody Version1.18
Emeric Vernat ≫ Javamelody Version1.19
Emeric Vernat ≫ Javamelody Version1.20
Emeric Vernat ≫ Javamelody Version1.21
Emeric Vernat ≫ Javamelody Version1.22
Emeric Vernat ≫ Javamelody Version1.23
Emeric Vernat ≫ Javamelody Version1.24
Emeric Vernat ≫ Javamelody Version1.25
Emeric Vernat ≫ Javamelody Version1.26
Emeric Vernat ≫ Javamelody Version1.27
Emeric Vernat ≫ Javamelody Version1.28
Emeric Vernat ≫ Javamelody Version1.29
Emeric Vernat ≫ Javamelody Version1.30
Emeric Vernat ≫ Javamelody Version1.31
Emeric Vernat ≫ Javamelody Version1.32
Emeric Vernat ≫ Javamelody Version1.32.1
Emeric Vernat ≫ Javamelody Version1.33
Emeric Vernat ≫ Javamelody Version1.34
Emeric Vernat ≫ Javamelody Version1.35
Emeric Vernat ≫ Javamelody Version1.36
Emeric Vernat ≫ Javamelody Version1.37
Emeric Vernat ≫ Javamelody Version1.38
Emeric Vernat ≫ Javamelody Version1.39
Emeric Vernat ≫ Javamelody Version1.40
Emeric Vernat ≫ Javamelody Version1.41
Emeric Vernat ≫ Javamelody Version1.42
Emeric Vernat ≫ Javamelody Version1.43
Emeric Vernat ≫ Javamelody Version1.44
Emeric Vernat ≫ Javamelody Version1.45
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1% | 0.765 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.