Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.
References
Configurations
History
No history.
Information
Published : 2015-06-26 10:59
Updated : 2017-09-23 01:29
NVD link : CVE-2015-1159
Mitre link : CVE-2015-1159
CVE.ORG link : CVE-2015-1159
JSON object : View
Products Affected
cups
- cups
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')