A cross-site scripting (XSS) vulnerability in the component /graphallperiods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "g" parameter.
{ "binaries": [ { "binary_name": "ganglia-webfrontend", "binary_version": "3.6.1-1ubuntu1.1" } ] }
{ "binaries": [ { "binary_name": "ganglia-webfrontend", "binary_version": "3.6.1-3" } ] }
{ "binaries": [ { "binary_name": "ganglia-webfrontend", "binary_version": "3.7.5+debian-4" } ] }
{ "binaries": [ { "binary_name": "ganglia-webfrontend", "binary_version": "3.7.6+debian-1.1" } ] }