apache guacamole CVE-2016-1566 is a vulnerability in Apache Guacamole
Published on February 2, 2017

Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by multiple users, allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename. NOTE: this vulnerability was fixed in guacamole.war on 2016-01-13, but the version number was not changed.

NVD


Products Associated with CVE-2016-1566

Want to know whenever a new CVE is published for Apache Guacamole? stack.watch will email you.

 

Exploit Probability

EPSS
0.22%
Percentile
44.29%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.