CVE-2015-1159
EPSS 58.8%Published: 6/26/2015Modified: 4/28/2026
Also known as:DEBIAN-CVE-2015-1159
Description
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.
Affected packages (1)
- Debian/cupsfrom 0, < 1.7.5-12