CVE-2013-4168: XSS
Published Nov 1, 2019
·Updated
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
Affected Software
7 affected componentsFixes available
debian/smokeping
2.7.3-32.7.3-4.12.8.2+ds-1
smokeping smokeping=2.6.9
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=18
Fedoraproject Fedora=19
Event History
Nov 1, 2019
CVE Published
via MITRE·07:12 PM
Data Sourced
via MITRE·07:12 PM
DescriptionWeakness
Aug 6, 2024
Data Sourced
via Debian·04:43 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-4168?
CVE-2013-4168 is considered a moderate severity Cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2013-4168?
To fix CVE-2013-4168, upgrade to Smokeping versions 2.7.3-3, 2.7.3-4.1, or 2.8.2+ds-1.
3
What software is affected by CVE-2013-4168?
CVE-2013-4168 affects Smokeping version 2.6.9 and various Debian and Fedora Linux distributions.
4
Can CVE-2013-4168 be exploited remotely?
Yes, CVE-2013-4168 can be exploited remotely through crafted input in the start and end time fields.
5
What impact does CVE-2013-4168 have on users?
CVE-2013-4168 can allow attackers to execute arbitrary scripts in the context of the user's browser.