Lucene search

K
cve[email protected]CVE-2007-5496
HistoryMay 23, 2008 - 3:32 p.m.

CVE-2007-5496

2008-05-2315:32:00
CWE-79
web.nvd.nist.gov
23
cve-2007-5496
cross-site scripting
xss vulnerability
setroubleshoot
local users
web script
html
access vector cache
avc
log entry
log file
sealert

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

5.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.9%

Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert.

Affected configurations

NVD
Node
redhatenterprise_linuxMatch5.0server
OR
redhatenterprise_linux_desktopMatch5client
AND
selinuxsetroubleshootMatch2.0.5

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

5.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.9%