Summary
Detail | |||
---|---|---|---|
Vendor | Snipsnap | First view | 2004-12-31 |
Product | Snipsnap | Last view | 2015-02-03 |
Version | 0.5.2a | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:snipsnap:snipsnap |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4.3 | 2015-02-03 | CVE-2014-9559 | Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1, and 1.0b2 allows remote attackers to inject arbitrary web script or HTML via the query parameter to /snipsnap-search. |
5 | 2004-12-31 | CVE-2004-1470 | CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
10051 | SnipSnap POST Request authenticate HTTP Response Splitting |
OpenVAS Exploits
id | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200409-23 (snipsnap) File : nvt/glsa_200409_23.nasl |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2004-09-17 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-200409-23.nasl - Type: ACT_GATHER_INFO |