CVE-2012-0040
EPSS 0.55%simplesamlphp - cross site scripting
發布日:2012/1/24修改日:2026/4/28
也稱為:DEBIAN-CVE-2012-0040
描述
Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.
受影響套件(2)
- Debian/simplesamlphpfrom 0, < 1.8.2-1
- Debian/simplesamlphpfrom 0, < 1.6.3-3