6.1
CVSSv3

CVE-2019-8953

Published: 20/02/2019 Updated: 14/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The HAProxy package prior to 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netgate haproxy

Exploits

# Exploit Title: pfSense 244-p1 (HAProxy Package 059_14) - Stored Cross-Site Scripting # Date: 13022019 # Exploit Author: Gionathan "John" Reale # Vendor Homepage: wwwpfsenseorg # Version: 244-p1/059_14 # Software Link: N/A # Google Dork: N/A # CVE:2019-8953 ################################################################## ...