4.3
CVSSv2

CVE-2013-2643

Published: 18/03/2014 Updated: 19/03/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance prior to 3.7.8.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) xss parameter in an allow action to rss.php, (2) msg parameter to end-user/errdoc.php, (3) h parameter to end-user/ftp_redirect.php, or (4) threat parameter to the Blocked component.

Vulnerable Product Search on Vulmon Subscribe to Product

sophos web_appliance_firmware

sophos web_appliance -

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20130403-0 > ======================================================================= title: Multiple vulnerabilities product: Sophos Web Protection Appliance vulnerable version: <= 3781 fixed version: 3782 impact: Critical CVE num ...
Sophos Web Protection Appliance version 3781 suffers from OS command injection, cross site scripting, and file disclosure vulnerabilities ...