CVE-2013-1871
Red Hat Satellite 5.6 - Cross-Site Scripting via Account EditAddress Type Parameter
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in account/EditAddress.do in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter.
References (6)
Core 6
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56952
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0148.html
Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=923467
Patch x_refsource_confirm
https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ac55c6656bb19b3b13f
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/103211
Various Sources vendor-advisory
x_refsource_suse
https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.html
Scores
EPSS
0.0159
EPSS Percentile
73.1%
Details
CWE
CWE-79
Status
published
Products (1)
redhat/satellite
5.6
Published
Feb 14, 2014
Tracked Since
Feb 18, 2026