Lucene search

K
cveMitreCVE-2014-5348
HistoryAug 19, 2014 - 7:55 p.m.

CVE-2014-5348

2014-08-1919:55:04
CWE-79
mitre
web.nvd.nist.gov
26
cve
2014
5348
cross-site scripting
xss
riverbed
stingray
traffic manager
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

52.8%

Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.

Affected configurations

Nvd
Node
riverbedsteelapp_traffic_managerMatch9.69620140312
VendorProductVersionCPE
riverbedsteelapp_traffic_manager9.6cpe:2.3:a:riverbed:steelapp_traffic_manager:9.6:9620140312:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

52.8%

Related for CVE-2014-5348