3.5
CVSSv2

CVE-2015-6494

Published: 28/10/2015 Updated: 28/10/2015
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x prior to 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

infinite automation systems mango automation 2.5.0

infinite automation systems mango automation 2.5.5

infinite automation systems mango automation 2.6.0

Exploits

Mango Automation 260 CSRF File Upload And Arbitrary JSP Code Execution Vendor: Infinite Automation Systems Inc Product web page: wwwinfiniteautomationcom/ Affected version: 252 and 260 beta (build 327) Summary: Mango Automation is a flexible SCADA, HMI And Automation software application that allows you to view, log, graph, anima ...