4.3
CVSSv2

CVE-2014-7280

Published: 21/10/2014 Updated: 08/09/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Web UI prior to 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.

Vulnerable Product Search on Vulmon Subscribe to Product

tenable web ui

Exploits

Nessus Web UI 233: Stored XSS ========================================================= CVE number: CVE-2014-7280 Permalink: wwwthesecurityfactorybe/permalink/nessus-stored-xsshtml Vendor advisory: wwwtenablecom/security/tns-2014-08 -- Info -- Nessus is a proprietary comprehensive vulnerability scanner which is developed by ...
Nessus Web UI version 233 suffers from a persistent cross site scripting vulnerability ...