First published: Thu Dec 05 2013(Updated: )
Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ganglia | =3.5.8 | |
Ganglia | =3.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6395 is classified as a medium-severity cross-site scripting vulnerability.
To fix CVE-2013-6395, update Ganglia Web to version 3.5.11 or later, which addresses this vulnerability.
The affected versions in CVE-2013-6395 are Ganglia Web versions 3.5.8 and 3.5.10.
CVE-2013-6395 is a cross-site scripting (XSS) vulnerability that allows remote code injection.
Yes, CVE-2013-6395 can potentially lead to data compromise by allowing attackers to inject and execute arbitrary scripts.