Unrated severityNVD Advisory· Published May 19, 2015· Updated May 6, 2026
CVE-2015-3988
CVE-2015-3988
Description
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.
Affected products
2- cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.openwall.com/lists/oss-security/2015/05/12/9nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2015/05/14/14nvdThird Party Advisory
- www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/74666nvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2015-1679.htmlnvd
- security.openstack.org/ossa/OSSA-2015-009.htmlnvd
News mentions
0No linked articles in our index yet.