1 results (0.001 seconds)
CVSS: 6.1EPSS: 4%CPEs: 5EXPL: 3

CVE-2017-18635 – novnc: XSS vulnerability via the messages propagated to the status field
https://notcve.org/view.php?id=CVE-2017-18635
25 Sep 2019 — An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. Se detectó una vulnerabilidad de tipo XSS en noVNC versiones anteriores a 0.6.2, en la que el servidor remoto VNC podía inyectar HTML arbitrario en la página web de noVNC por medio de los mensajes propagados hacia el campo status, tales como el nombre del servidor VNC. An XSS vulnerability wa... • https://github.com/ShielderSec/CVE-2017-18635 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •