4.3
CVSSv2

CVE-2014-2856

Published: 18/04/2014 Updated: 16/12/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) prior to 1.7.2 allows remote malicious users to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups 1.1.12

apple cups 1.1.13

apple cups 1.1.19

apple cups 1.1.20

apple cups 1.1.22

apple cups 1.1.5-2

apple cups 1.1.6

apple cups 1.1.6-1

apple cups 1.2

apple cups 1.2.11

apple cups 1.2.12

apple cups 1.2.9

apple cups 1.3

apple cups 1.3.2

apple cups 1.3.3

apple cups 1.4

apple cups 1.4.5

apple cups 1.4.6

apple cups 1.5.0

apple cups 1.5

apple cups 1.6

apple cups 1.1.1

apple cups 1.1.10

apple cups 1.1.16

apple cups 1.1.17

apple cups 1.1.2

apple cups 1.1.21

apple cups 1.1.3

apple cups 1.1.4

apple cups 1.1.7

apple cups 1.1.8

apple cups 1.2.0

apple cups 1.2.4

apple cups 1.2.5

apple cups 1.3.0

apple cups 1.3.1

apple cups 1.3.6

apple cups 1.3.7

apple cups 1.4.0

apple cups 1.4.1

apple cups 1.4.2

apple cups 1.5.4

apple cups 1.5.3

apple cups 1.6.4

apple cups 1.6.3

apple cups 1.7

apple cups 1.1

apple cups 1.1.14

apple cups 1.1.15

apple cups 1.1.23

apple cups 1.1.6-2

apple cups 1.1.6-3

apple cups 1.2.2

apple cups 1.2.3

apple cups 1.3.4

apple cups 1.3.5

apple cups 1.4.7

apple cups 1.4.8

apple cups 1.7.1

apple cups

apple cups 1.7.0

apple cups 1.1.10-1

apple cups 1.1.11

apple cups 1.1.18

apple cups 1.1.5

apple cups 1.1.5-1

apple cups 1.1.9

apple cups 1.1.9-1

apple cups 1.2.1

apple cups 1.2.10

apple cups 1.2.6

apple cups 1.2.7

apple cups 1.2.8

apple cups 1.3.10

apple cups 1.3.11

apple cups 1.3.8

apple cups 1.3.9

apple cups 1.4.3

apple cups 1.4.4

apple cups 1.5.2

apple cups 1.5.1

apple cups 1.6.2

apple cups 1.6.1

Vendor Advisories

CUPS could be made to expose sensitive information over the network ...
A cross-site scripting (XSS) flaw was found in the CUPS web interface An attacker could use this flaw to perform a cross-site scripting attack against users of the CUPS web interface (CVE-2014-2856) It was discovered that CUPS allowed certain users to create symbolic links in certain directories under /var/cache/cups/ A local user with the 'lp' ...
A cross-site scripting (XSS) flaw was found in the CUPS web interface An attacker could use this flaw to perform a cross-site scripting attack against users of the CUPS web interface ...