CVE-2015-1159
cups: cross-site scripting flaw in CUPS web UI (VU#810572)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.
Vulnerabilidad de XSS en la función cgi_puts en cgi-bin/template.c en el motor de plantillas en CUPS anterior a 2.0.3 permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través del parámetro QUERY en help/.
A cross-site scripting flaw was found in the cups web templating engine. An attacker could use this flaw to bypass the default configuration settings that bind the CUPS scheduler to the 'localhost' or loopback interface.
CUPS versions prior to 2.0.3 suffers from improper teardown and cross site scripting vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-16 CVE Reserved
- 2015-06-10 CVE Published
- 2024-07-20 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://googleprojectzero.blogspot.in/2015/06/owning-internet-printing-case-study-in.html | Technical Description | |
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10702 | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/810572 | Third Party Advisory | |
http://www.securityfocus.com/bid/75106 | Third Party Advisory | |
http://www.securitytracker.com/id/1032556 | Vdb Entry | |
https://bugzilla.opensuse.org/show_bug.cgi?id=924208 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://code.google.com/p/google-security-research/issues/detail?id=455 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00003.html | 2017-09-23 | |
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00006.html | 2017-09-23 | |
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00010.html | 2017-09-23 | |
http://rhn.redhat.com/errata/RHSA-2015-1123.html | 2017-09-23 | |
http://www.cups.org/blog.php?L1082 | 2017-09-23 | |
http://www.debian.org/security/2015/dsa-3283 | 2017-09-23 | |
http://www.ubuntu.com/usn/USN-2629-1 | 2017-09-23 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1221642 | 2015-06-17 | |
https://security.gentoo.org/glsa/201510-07 | 2017-09-23 | |
https://www.cups.org/str.php?L4609 | 2017-09-23 | |
https://access.redhat.com/security/cve/CVE-2015-1159 | 2015-06-17 |