Vulnerabilities > Apache > Solr

DATE CVE VULNERABILITY TITLE RISK
2016-02-15 CVE-2015-8797 Cross-site Scripting vulnerability in Apache Solr
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.
network
low complexity
apache CWE-79
6.1
2016-02-15 CVE-2015-8796 Cross-site Scripting vulnerability in Apache Solr
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.
network
low complexity
apache CWE-79
6.1
2016-02-15 CVE-2015-8795 Cross-site Scripting vulnerability in Apache Solr
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.
network
low complexity
apache CWE-79
6.1