CVE-2014-4301
Published Jun 18, 2014
Last updated 8 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ajenti:ajenti:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "40A0F389-FFD9-4A3B-834D-590E82C3FA2C", "versionEndIncluding": "1.2.21" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7B0A64A-B7C0-4C26-9D99-C62EC55E7798" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D993FFE-EC2F-47B8-9977-584C5A45DE72" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A910951-0BB7-4D81-85F6-92C33C483A8E" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "984A2F17-4D28-4773-A83F-D1AD9C5C3643" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A55937EB-97D4-4E14-B277-C82B1D1C15F9" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7584CB68-1F09-4974-88E7-E0F83776AC6B" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE69A990-4D12-4F75-85D3-D8527C1C64FA" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BBD60311-4A22-4FF8-8FAB-7EF872DE3ECF" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8FB0745-DAFE-4A9F-A6D0-ABAF9A937F4A" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13E6C3AF-15AD-4897-8A71-C05FFD94081B" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4C7941B-9116-48C7-B529-A97DE13D64F7" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EAABC566-E783-47A8-A375-5D39B6342EE7" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B5FFC25-9E65-4AC2-9036-8D6737FF98AB" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8585A18-570A-4F8A-8F25-7361AA034210" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4EC2C47B-CAA5-4804-ABD2-4373D08457AA" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0757415-9675-4FC1-BAAC-C4ACAE92802B" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9CD3FF52-5171-4FCB-B7F9-14401D0A0130" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE8B485A-4232-4232-8BC1-62201BBAF095" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F6A18C3B-445D-4C7F-911A-BF1C5D8998E7" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "006EAD4D-140C-4D17-92EA-102565B61801" }, { "criteria": "cpe:2.3:a:ajenti:ajenti:1.2.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BA6F8FE-EF7D-4712-82E9-09E65479C993" } ], "operator": "OR" } ] } ]