Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Server Gateway (DSGW) web interface in Red Hat Directory Server 7.1 before SP7 and 8 EL4 and EL5, and Fedora Directory Server, allow remote attackers to inject arbitrary web script or HTML via input values that use % (percent) escaping.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Hpux | — | Update NetscapeDirSvr7.NDS-NSPERL to the latest versionUpdate NetscapeDirSvr6.NDS-NC to the latest versionUpdate NetscapeDirSvr7.NDS-SLCLNT to the latest versionUpdate NetscapeDirSvr6.NDS-SVCORE to the latest versionUpdate NetscapeDirSvr7.NDS-BSJRE to the latest versionUpdate NetscapeDirSvr6.NDS-SLCLNT to the latest versionUpdate NetscapeDirSvr6.NDS-SLAPD to the latest versionUpdate NetscapeDirSvr7.NDS-NC to the latest versionUpdate NetscapeDirSvr6.NDS-BSCLNT to the latest versionUpdate NetscapeDirSvr6.NDS-NSPERL to the latest versionUpdate NetscapeDirSvr7.NDS-ADM to the latest versionUpdate NetscapeDirSvr7.NDS-SVCORE to the latest versionUpdate NetscapeDirSvr7.NDS-RUN to the latest versionUpdate NetscapeDirSvr6.NDS-BASE to the latest versionUpdate NetscapeDirSvr7.NDS-BASE to the latest versionUpdate NetscapeDirSvr7.NDS-PERLDAP to the latest versionUpdate NetscapeDirSvr7.NDS-SLAPD to the latest versionUpdate NetscapeDirSvr7.NDS-BSCLNT to the latest versionUpdate NetscapeDirSvr6.NDS-PERLDAP to the latest versionUpdate NetscapeDirSvr6.NDS-BSJRE to the latest versionUpdate NetscapeDirSvr6.NDS-ADM to the latest version | Aug 11, 2017 | Aug 29, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub