CVE-2014-3207

Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to pks/lookup/undefined1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sks_keyserver_project:sks_keyserver:*:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:sks_keyserver_project:sks_keyserver:1.1.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-05-08 14:29

Updated : 2024-02-04 18:35


NVD link : CVE-2014-3207

Mitre link : CVE-2014-3207

CVE.ORG link : CVE-2014-3207


JSON object : View

Products Affected

sks_keyserver_project

  • sks_keyserver
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')