• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2015-1159
  1. CVEs

CVE-2015-1159

medium
  • Information
  • CPEs
  • Plugins

Description

Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.

References

http://googleprojectzero.blogspot.in/2015/06/owning-internet-printing-case-study-in.html

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10702

http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00006.html

http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00010.html

http://rhn.redhat.com/errata/RHSA-2015-1123.html

http://www.cups.org/blog.php?L1082

http://www.debian.org/security/2015/dsa-3283

http://www.kb.cert.org/vuls/id/810572

http://www.securityfocus.com/bid/75106

http://www.securitytracker.com/id/1032556

http://www.ubuntu.com/usn/USN-2629-1

https://bugzilla.opensuse.org/show_bug.cgi?id=924208

https://bugzilla.redhat.com/show_bug.cgi?id=1221642

https://code.google.com/p/google-security-research/issues/detail?id=455

https://security.gentoo.org/glsa/201510-07

https://www.cups.org/str.php?L4609

Details

Source: MITRE

Published: 2015-06-26

Updated: 2017-09-23

Type: CWE-79

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance