CVE-2013-1871Cross-site Scripting in Redhat Satellite

Severity
3.5LOWNVD
EPSS
0.3%
top 47.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateMay 13

Description

Cross-site scripting (XSS) vulnerability in account/EditAddress.do in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6jqg-mmw8-392m: Cross-site scripting (XSS) vulnerability in account/EditAddress2022-05-13
CVEList
CVE-2013-1871: Cross-site scripting (XSS) vulnerability in account/EditAddress2014-02-14

💥Exploits & PoCs

1
Exploit-DB
JBoss Seam 2 - Arbitrary File Upload / Execution (Metasploit)2015-04-06

📋Vendor Advisories

1
Red Hat
Satellite/Spacewalk: XSS in EditAddress page2014-02-10

💬Community

1
Bugzilla
CVE-2013-1871 Satellite/Spacewalk: XSS in EditAddress page2013-03-19
CVE-2013-1871 — Cross-site Scripting in Redhat | cvebase