ShielderSec/CVE-2017-18635

ShielderSec/CVE-2017-18635

Releases0
Stars5
PoC for CVE-2017-18635

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM4.3 MEDIUM

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.