← Vulnerability feed

Vulnerability record · CVE-2015-1159 · published 26 June 2015

CVE-2015-1159: Cups cross-site scripting vulnerability

Cups · Cups

Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.

4.3 CVSS 2.0 Medium EPSS 7.3% · top 5.8% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
7.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://googleprojectzero.blogspot.in/2015/06/owning-internet-printing-case-study-in.html Technical Description
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10702 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00010.html
http://rhn.redhat.com/errata/RHSA-2015-1123.html
http://www.cups.org/blog.php?L1082 Vendor Advisory
http://www.debian.org/security/2015/dsa-3283
http://www.kb.cert.org/vuls/id/810572 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/75106 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1032556
http://www.ubuntu.com/usn/USN-2629-1
https://bugzilla.opensuse.org/show_bug.cgi?id=924208 Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1221642 Issue Tracking
https://code.google.com/p/google-security-research/issues/detail?id=455 Exploit
https://security.gentoo.org/glsa/201510-07 Third Party AdvisoryVDB Entry
https://www.cups.org/str.php?L4609 Vendor Advisory
http://googleprojectzero.blogspot.in/2015/06/owning-internet-printing-case-study-in.html Technical Description
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10702 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00010.html
http://rhn.redhat.com/errata/RHSA-2015-1123.html
http://www.cups.org/blog.php?L1082 Vendor Advisory
http://www.debian.org/security/2015/dsa-3283
http://www.kb.cert.org/vuls/id/810572 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/75106 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1032556
http://www.ubuntu.com/usn/USN-2629-1
https://bugzilla.opensuse.org/show_bug.cgi?id=924208 Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1221642 Issue Tracking
https://code.google.com/p/google-security-research/issues/detail?id=455 Exploit
https://security.gentoo.org/glsa/201510-07 Third Party AdvisoryVDB Entry
https://www.cups.org/str.php?L4609 Vendor Advisory

Track CVE-2015-1159 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-1158Cups vulnerabilityThe add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name…EPSS 30%10.0CVE-2008-0882Cups memory buffer overflow vulnerabilityDouble free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and p…EPSS 5.8%10.0CVE-2007-4351Cups vulnerabilityOff-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1)…EPSS 7.4%9.3CVE-2008-0047Cups memory buffer overflow vulnerabilityHeap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.…EPSS 6.8%8.8CVE-2018-6553Cups vulnerabilityThe CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape c…EPSS 0.39%8.8CVE-2014-8166Cups improper input validation vulnerabilityThe browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to exe…EPSS 3.7%7.5CVE-2005-4873Cups memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code …EPSS 1.9%5.0CVE-2007-0720Cups vulnerabilityThe CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connectio…EPSS 5.3%

Source: NIST National Vulnerability Database (record CVE-2015-1159), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.