4.3
CVSSv2

CVE-2013-2639

Published: 11/02/2014 Updated: 30/07/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS prior to 3.2.29.0, 3.2.42.0, and previous versions allows remote malicious users to inject arbitrary web script or HTML via the description in a project folder.

Vulnerable Product Search on Vulmon Subscribe to Product

ctera cloud storage os 3.2.29.0

ctera cloud storage os 3.2.42.0

Exploits

# Exploit Title: [CTERA Project Folders - Stored XSS]   # Date: [11-Mar-2013] # Exploit Author: [Luigi Vezzoso] # Vendor Homepage: [wwwcteracom] # Version: [32290 and 32420 ] # Tested on: [ctera os] # CVE : [CVE-2013-2639]   #OVERVIEW Standard Ctera User can define a particular “description” for a ProjectFolder that cause java ...