4.3
CVSSv2

CVE-2013-5911

Published: 24/09/2013 Updated: 15/10/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 up to and including 4.7 allows remote malicious users to inject arbitrary web script or HTML via the message parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

tenable securitycenter 4.6

tenable securitycenter 4.7

Vendor Advisories

SecurityCenter contains a flaw that allows a reflected cross-site scripting (XSS) attack This flaw exists because the application does not validate the 'message' parameter upon submission to the devformphp script This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within t ...