4.3
CVSSv2

CVE-2018-18370

Published: 30/08/2019 Updated: 08/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in the WebFTP mode allows a remote malicious user to inject malicious JavaScript code in ASG/ProxySG's web listing of a remote FTP server. Exploiting the vulnerability requires the malicious user to be able to upload crafted files to the remote FTP server. Affected versions: ASG 6.6 and 6.7 before 6.7.4.2; ProxySG 6.5 before 6.5.10.15, 6.6, and 6.7 before 6.7.4.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

broadcom advanced secure gateway 6.6

broadcom advanced secure gateway

broadcom symantec proxysg

broadcom symantec proxysg 6.6