4.3
CVSSv2

CVE-2015-1159

Published: 26/06/2015 Updated: 23/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS prior to 2.0.3 allows remote malicious users to inject arbitrary web script or HTML via the QUERY parameter to help/.

Vulnerable Product Search on Vulmon Subscribe to Product

cups cups

Vendor Advisories

Several security issues were fixed in CUPS ...
A string reference count bug was found in cupsd, causing premature freeing of string objects An attacker can submit a malicious print job that exploits this flaw to dismantle ACLs protecting privileged operations, allowing a replacement configuration file to be uploaded which in turn allows the attacker to run arbitrary code in the CUPS server (CV ...
A cross-site scripting flaw was found in the cups web templating engine An attacker could use this flaw to bypass the default configuration settings that bind the CUPS scheduler to the 'localhost' or loopback interface ...

Exploits

CUPS versions prior to 203 suffers from improper teardown and cross site scripting vulnerabilities ...