Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.
References
Configurations
Information
Published : 2015-06-26 03:59
Updated : 2017-09-22 18:29
NVD link : CVE-2015-1159
Mitre link : CVE-2015-1159
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
cups
- cups