CVE-2016-6800
published 2017-08-30CVE-2016-6800: The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific…
PriorityP431medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
3.11%
86.3th percentile
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaScript code in these form fields. This code gets executed from the browser of every user who is visiting this article. Mitigation: Upgrade to Apache OFBiz 16.11.01.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco7.8HIGH
vendor_apache6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS and NX-OS Software Locator/ID Separation Protocol Packet Denial of Service Vulnerability
vendor_cisco·2016-03-23·CVSS 7.8
CVE-2016-1351 [HIGH] CWE-399 Cisco IOS and NX-OS Software Locator/ID Separation Protocol Packet Denial of Service Vulnerability
Cisco IOS and NX-OS Software Locator/ID Separation Protocol Packet Denial of Service Vulnerability
A vulnerability in the Locator/ID Separation Protocol (LISP) of Cisco IOS Software running on the Cisco Catalyst 6500 and 6800 Series Switches and Cisco NX-OS Software running on the Cisco Nexus 7000 and Nexus 7700 Series Switches with an M1 Series Gigabit Ethernet Module could allow an unauthenticated, remote attacker to cause a reload of the vulnerable device.
The vulnerability is due to a lack of proper input validation when a malformed LISP packet header is received. An attacker could exploit this vulnerability by sending a malformed LISP packet on UDP port 4341. An exploit could allow the attacker to cause a denial of service (DoS) condition.
Cisco has released software updates that a
Apache
Apache ofbiz: CVE-2016-6800
vendor_apache·CVSS 6.1
CVE-2016-6800 [MEDIUM] Apache ofbiz: CVE-2016-6800
Apache ofbiz: CVE-2016-6800
; affected releases: 13.07.*, 12.04.*, 11.04.*; fixed in 16.11.01 with revisions 1759065 and 1759218
Cisco
Cisco IOS and NX-OS Software Locator/ID Separation Protocol Packet Denial of Service Vulnerability
vendor_cisco
CVE-2016-1351 Cisco IOS and NX-OS Software Locator/ID Separation Protocol Packet Denial of Service Vulnerability
CVE-2016-1351: Cisco IOS and NX-OS Software Locator/ID Separation Protocol Packet Denial of Service Vulnerability
A vulnerability in the Locator/ID Separation Protocol (LISP) of Cisco IOS Software running on the Cisco Catalyst 6500 and 6800 Series Switches and Cisco NX-OS Software running on the Cisco Nexus 7000 and Nexus 7700 Series Switches with an M1 Series Gigabit Ethernet Module could allow an unauthenticated, remote attacker to cause a reload of the vulnerable device. The vulnerability is due to a lack of proper input validation when a malformed LISP packet header is received. An attacker could exploit this vulnerability by sending a malformed LISP packet on UDP port 4341. An exploit could allow the attacker to cause a denial of service (DoS) condition. Cisco has released software up
GHSA
GHSA-5r8q-h585-cc8r: The default configuration of the Apache OFBiz framework offers a blog functionality
ghsa_unreviewed·2022-05-13
CVE-2016-6800 [MEDIUM] CWE-79 GHSA-5r8q-h585-cc8r: The default configuration of the Apache OFBiz framework offers a blog functionality
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaScript code in these form fields. This code gets executed from the browser of every user who is visiting this article. Mitigation: Upgrade to Apache OFBiz 16.11.01.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-30
Published