PT-2015-7290 · Opentext · Opentext Secure Mft
Alexander Stra�Heim
+1
·
Publicado
2015-08-20
·
Atualizado
2018-10-09
·
CVE-2015-6530
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenText Secure MFT versions 2013 before 2013 R3 P6
OpenText Secure MFT versions 2014 before 2014 R2 P2
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the
querytext parameter to the "userdashboard.jsp" endpoint.Recommendations
For OpenText Secure MFT versions 2013 before 2013 R3 P6, update to version 2013 R3 P6 or later.
For OpenText Secure MFT versions 2014 before 2014 R2 P2, update to version 2014 R2 P2 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opentext Secure Mft