CVE-2013-0275: XSS
A number of XSS flaws were reported in the Ganglia web frontend.
These flaws are not currently public.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in Ganglia Web before 3.5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0275?
The severity of CVE-2013-0275 is considered to be significant due to the potential for remote attackers to exploit the XSS vulnerabilities.
How do I fix CVE-2013-0275?
To fix CVE-2013-0275, upgrade to Ganglia Web version 3.5.6 or later, as these versions contain patches for the identified vulnerabilities.
What types of vulnerabilities are associated with CVE-2013-0275?
CVE-2013-0275 is associated with multiple cross-site scripting (XSS) vulnerabilities that allow for arbitrary web script or HTML injection.
Which versions of Ganglia Web are affected by CVE-2013-0275?
Versions of Ganglia Web prior to 3.5.6 and specific versions such as 2.1.0 through 3.5.5 are affected by CVE-2013-0275.
Can CVE-2013-0275 be exploited remotely?
Yes, CVE-2013-0275 can be exploited remotely, allowing attackers to execute scripts in the context of the victim's browser.