4.3
CVSSv2

CVE-2010-2914

Published: 30/07/2010 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

nessus web_server_plugin 1.2.4

Vendor Advisories

Nessus contains a flaw that allows a reflected cross-site scripting (XSS) attack This flaw exists because the Web GUI (nessusd_www_servernbin) does not validate unspecified input to a GET parameter before returning it to users This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script co ...