6.1
CVSSv3

CVE-2018-20503

Published: 07/05/2019 Updated: 08/05/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alliedtelesis 8100l\\/8_firmware -

Exploits

# Exploit Title: SirsiDynix e-Library <= 35x - Cross-Site Scripting # CVE: CVE-2018-20503 # Date: 2019-24-01 # Google Dork: inurl:/x/x/0/49 # Exploit Author: Özkan Mustafa Akkuş (AkkuS) # Contact: pentestcomtr # Vendor Homepage: wwwsirsidynixcom # Version: 35x # Category: Webapps # Tested on: Firefox/52 and Chrome/69 # S ...
SirsiDynix e-Library version 35x suffers from a cross site scripting vulnerability ...