Lucene search

K
nvd[email protected]NVD:CVE-2013-4674
HistoryJul 31, 2013 - 1:20 p.m.

CVE-2013-4674

2013-07-3113:20:28
CWE-79
web.nvd.nist.gov
4

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.1

Confidence

High

EPSS

0.006

Percentile

79.2%

Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted encrypted e-mail attachment.

Affected configurations

Nvd
Node
symantecencryption_management_serverRange3.3.0mp1
OR
symantecencryption_management_serverMatch3.3.0
OR
symantecpgp_universal_serverMatch3.2.0
OR
symantecpgp_universal_serverMatch3.2.1
OR
symantecpgp_universal_serverMatch3.2.1mp2
VendorProductVersionCPE
symantecencryption_management_server*cpe:2.3:a:symantec:encryption_management_server:*:mp1:*:*:*:*:*:*
symantecencryption_management_server3.3.0cpe:2.3:a:symantec:encryption_management_server:3.3.0:*:*:*:*:*:*:*
symantecpgp_universal_server3.2.0cpe:2.3:a:symantec:pgp_universal_server:3.2.0:*:*:*:*:*:*:*
symantecpgp_universal_server3.2.1cpe:2.3:a:symantec:pgp_universal_server:3.2.1:*:*:*:*:*:*:*
symantecpgp_universal_server3.2.1cpe:2.3:a:symantec:pgp_universal_server:3.2.1:mp2:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.1

Confidence

High

EPSS

0.006

Percentile

79.2%

Related for NVD:CVE-2013-4674