FireGPG PGP Key Issuer Name HTML...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

FireGPG is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content. Attacker-supplied HTML or JavaScript code could run in the context of the website that the application is triggered from, potentially allowing an attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible. This issue affects FireGPG 0.4.6; prior versions may also be affected. Sun StarSuite 8 Sun StarOffice 8.0 S.u.S.E. SUSE Linux Enterprise Desktop 10 SP1 S.u.S.E. SLE SDK 10.SP1 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc RedHat Fedora 8 0 RedHat Fedora 7 0 RedHat Fedora Core6 RedHat Enterprise Linux Optional Productivity Application v.5 server RedHat Enterprise Linux Desktop v.5...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息