Lucene search

K
cveSymantecCVE-2014-1652
HistoryJun 18, 2014 - 7:55 p.m.

CVE-2014-1652

2014-06-1819:55:04
CWE-79
symantec
web.nvd.nist.gov
28
cve-2014-1652
cross-site scripting
xss
symantec web gateway
swg
remote authenticated users
web script injection

CVSS2

2.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:A/AC:M/Au:S/C:N/I:P/A:N

AI Score

7.4

Confidence

Low

EPSS

0.26

Percentile

96.7%

Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec Web Gateway (SWG) before 5.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified report parameters.

Affected configurations

Nvd
Node
symantecweb_gatewayRange5.1.1
OR
symantecweb_gatewayMatch5.1
VendorProductVersionCPE
symantecweb_gateway*cpe:2.3:a:symantec:web_gateway:*:*:*:*:*:*:*:*
symantecweb_gateway5.1cpe:2.3:a:symantec:web_gateway:5.1:*:*:*:*:*:*:*

CVSS2

2.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:A/AC:M/Au:S/C:N/I:P/A:N

AI Score

7.4

Confidence

Low

EPSS

0.26

Percentile

96.7%