Description
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
References (10)
Core 10
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/57880
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/66788
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2172-1
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/04/14/2
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1388.html
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2014-0193.html
Various Sources x_refsource_confirm
http://www.cups.org/documentation.php/relnotes.html
Various Sources x_refsource_confirm
http://www.cups.org/str.php?L4356
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/04/15/3
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:108
Scores
EPSS
0.0164
EPSS Percentile
73.9%
Details
CWE
CWE-79
Status
published
Products (32)
apple/cups
1.1
apple/cups
1.1.1
apple/cups
1.1.2
apple/cups
1.1.3
apple/cups
1.1.4
apple/cups
1.1.5
apple/cups
1.1.5-1
apple/cups
1.1.5-2
apple/cups
1.1.6
apple/cups
1.1.6-1
... and 22 more
Published
Apr 18, 2014
Tracked Since
Feb 18, 2026