4.3
CVSSv2

CVE-2009-2959

Published: 25/08/2009 Updated: 25/08/2009
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 up to and including 0.7.11p1 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

buildbot buildbot 0.7.11p1

buildbot buildbot 0.7.10p1

buildbot buildbot 0.7.8

buildbot buildbot 0.7.10

buildbot buildbot 0.7.6

buildbot buildbot 0.7.7

buildbot buildbot 0.7.9

buildbot buildbot 0.7.11

Vendor Advisories

Debian Bug report logs - #543822 CVE-2009-2959: Cross-site scripting (XSS) vulnerability Package: buildbot; Maintainer for buildbot is Python Applications Packaging Team <python-apps-team@listsaliothdebianorg>; Source for buildbot is src:buildbot (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <giuseppe@iuculanoi ...