Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Alex Korobkin

#50793de 53,638
4.3CVSS total
Vulnerabilidades · 1
PT-2014-4923
4.3
2014-04-18
Apple · Cups · CVE-2014-2856
**Name of the Vulnerable Software and Affected Versions** CUPS versions prior to 1.7.2 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the `is path absolute` function. This is due to a flaw in the scheduler/client.c component of the Common Unix Printing System (CUPS). **Recommendations** For versions prior to 1.7.2, update to version 1.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the scheduler/client.c component to minimize the risk of exploitation.