CVE-2013-4378

Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
emeric_vernatjavamelody
𝑥
≤ 1.46
emeric_vernatjavamelody
1.6
emeric_vernatjavamelody
1.7
emeric_vernatjavamelody
1.8
emeric_vernatjavamelody
1.9
emeric_vernatjavamelody
1.10
emeric_vernatjavamelody
1.11
emeric_vernatjavamelody
1.12
emeric_vernatjavamelody
1.13
emeric_vernatjavamelody
1.14
emeric_vernatjavamelody
1.15
emeric_vernatjavamelody
1.16
emeric_vernatjavamelody
1.17
emeric_vernatjavamelody
1.18
emeric_vernatjavamelody
1.19
emeric_vernatjavamelody
1.20
emeric_vernatjavamelody
1.21
emeric_vernatjavamelody
1.22
emeric_vernatjavamelody
1.23
emeric_vernatjavamelody
1.24
emeric_vernatjavamelody
1.25
emeric_vernatjavamelody
1.26
emeric_vernatjavamelody
1.27
emeric_vernatjavamelody
1.28
emeric_vernatjavamelody
1.29
emeric_vernatjavamelody
1.30
emeric_vernatjavamelody
1.31
emeric_vernatjavamelody
1.32
emeric_vernatjavamelody
1.32.1
emeric_vernatjavamelody
1.33
emeric_vernatjavamelody
1.34
emeric_vernatjavamelody
1.35
emeric_vernatjavamelody
1.36
emeric_vernatjavamelody
1.37
emeric_vernatjavamelody
1.38
emeric_vernatjavamelody
1.39
emeric_vernatjavamelody
1.40
emeric_vernatjavamelody
1.41
emeric_vernatjavamelody
1.42
emeric_vernatjavamelody
1.43
emeric_vernatjavamelody
1.44
emeric_vernatjavamelody
1.45
𝑥
= Vulnerable software versions