CVE-2015-1864
Summary
| CVE | CVE-2015-1864 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-19 15:29:00 UTC |
| Updated | 2020-05-28 16:59:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kallithea-scm | Kallithea | 0.1 | All | All | All |
| Application | Kallithea-scm | Kallithea | 0.2 | All | All | All |
| Application | Kallithea-scm | Kallithea | 0.1 | All | All | All |
| Application | Kallithea-scm | Kallithea | 0.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Kallithea · Security Notice CVE-2015-1864 | CONFIRM | kallithea-scm.org | Exploit, Vendor Advisory |
| Kallithea CVE-2015-1864 Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| oss-security - CVE-2015-1864: Multiple HTML and Javascript injections | MLIST | www.openwall.com | Exploit, Mailing List, Third Party Advisory |
| kallithea Changeset - a8f2986afc18 · Our Own Kallithea | CONFIRM | kallithea-scm.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.