A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "tz" parameter.
{ "binaries": [ { "binary_version": "3.7.5+debian-4", "binary_name": "ganglia-webfrontend" } ] }
{ "binaries": [ { "binary_version": "3.7.6+debian-1.1", "binary_name": "ganglia-webfrontend" } ] }
{ "binaries": [ { "binary_version": "3.6.1-1ubuntu1.1", "binary_name": "ganglia-webfrontend" } ] }
{ "binaries": [ { "binary_version": "3.6.1-3", "binary_name": "ganglia-webfrontend" } ] }