4.3
CVSSv2

CVE-2017-12971

Published: 23/08/2017 Updated: 03/05/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote malicious users to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache2triad apache2triad 1.5.4

Exploits

[+] Credits: John Page AKA hyp3rlinx [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/APACHE2TRIAD-SERVER-STACK-v154-MULTIPLE-CVEtxt [+] ISR: ApparitionSec Vendor: =============== apache2triadnet sourceforgenet/projects/apache2triad/ Product: =========== Apache2Triad v15 ...
Apache2Triad version 154 suffers from session fixation, cross site request forgery, and cross site scripting vulnerabilities ...