Vulnerabilities > Apache > Solr > 1.1.0

DATE CVE VULNERABILITY TITLE RISK
2016-02-15 CVE-2015-8796 Cross-site Scripting vulnerability in Apache Solr
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.
network
apache CWE-79
4.3
2016-02-15 CVE-2015-8795 Cross-site Scripting vulnerability in Apache Solr
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.
network
apache CWE-79
4.3
2013-12-07 CVE-2012-6612 Unspecified vulnerability in Apache Solr
The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.
network
low complexity
apache
7.5
2013-12-07 CVE-2013-6407 XML External Entity Injection vulnerability in Apache Solr
The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
apache
6.4