Lucene search

K
cve[email protected]CVE-2014-5343
HistoryAug 19, 2014 - 6:55 p.m.

CVE-2014-5343

2014-08-1918:55:03
CWE-79
web.nvd.nist.gov
19
cve-2014-5343
cross-site scripting
xss
vulnerability
feng office
remote attackers
web script
html
name field

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.0%

Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.

Affected configurations

NVD
Node
fengofficefeng_officeMatch1.6.2
OR
fengofficefeng_officeMatch1.7
OR
fengofficefeng_officeMatch1.7beta
OR
fengofficefeng_officeMatch1.7beta2
OR
fengofficefeng_officeMatch1.7rc
OR
fengofficefeng_officeMatch1.7rc2
OR
fengofficefeng_officeMatch1.7rc3
OR
fengofficefeng_officeMatch1.7.1
OR
fengofficefeng_officeMatch1.7.2
OR
fengofficefeng_officeMatch1.7.3.1
OR
fengofficefeng_officeMatch1.7.4
OR
fengofficefeng_officeMatch1.7.5
OR
fengofficefeng_officeMatch1.7.5beta
OR
fengofficefeng_officeMatch1.7.5rc2
OR
fengofficefeng_officeMatch1.7.5rc3
OR
fengofficefeng_officeMatch2.0.0
OR
fengofficefeng_officeMatch2.0.0beta1
OR
fengofficefeng_officeMatch2.0.0beta2
OR
fengofficefeng_officeMatch2.0.0beta3
OR
fengofficefeng_officeMatch2.0.0beta4
OR
fengofficefeng_officeMatch2.0.0rc
OR
fengofficefeng_officeMatch2.1.0
OR
fengofficefeng_officeMatch2.1.0beta
OR
fengofficefeng_officeMatch2.1.0rc
OR
fengofficefeng_officeMatch2.1.0rc2
OR
fengofficefeng_officeMatch2.2.0
OR
fengofficefeng_officeMatch2.2.0beta
OR
fengofficefeng_officeMatch2.2.0rc
OR
fengofficefeng_officeMatch2.2.1
OR
fengofficefeng_officeMatch2.2.1rc
OR
fengofficefeng_officeMatch2.2.2
OR
fengofficefeng_officeMatch2.2.3.1
OR
fengofficefeng_officeMatch2.2.3.1beta
OR
fengofficefeng_officeMatch2.2.4
OR
fengofficefeng_officeMatch2.2.4beta
OR
fengofficefeng_officeMatch2.2.4.1
OR
fengofficefeng_officeMatch2.3
OR
fengofficefeng_officeMatch2.3beta
OR
fengofficefeng_officeMatch2.3rc
OR
fengofficefeng_officeMatch2.3rc2
OR
fengofficefeng_officeMatch2.3.1
OR
fengofficefeng_officeMatch2.3.1beta
OR
fengofficefeng_officeMatch2.3.1rc
OR
fengofficefeng_officeMatch2.3.1.1
OR
fengofficefeng_officeMatch2.3.2
OR
fengofficefeng_officeMatch2.3.2beta
OR
fengofficefeng_officeMatch2.3.2rc
OR
fengofficefeng_officeMatch2.3.2rc2
OR
fengofficefeng_officeMatch2.3.2.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.0%

Related for CVE-2014-5343