PT-2015-7533 · Ca Technologies+2 · Ca Release Automation+2
Sergey Markov
·
Publicado
2015-10-14
·
Atualizado
2018-10-09
·
CVE-2015-7370
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Open Flash Chart 2
Revive Adserver versions prior to 3.2.2
CA Release Automation versions prior to 5.0.2-227
CA Release Automation versions prior to 5.5.1-1616
CA Release Automation versions prior to 5.5.2-434
CA Release Automation versions prior to 6.1.0-1026
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
id or data-file parameter, potentially leading to cross-site scripting (XSS) attacks.Recommendations
For Open Flash Chart 2, update to a version that is not affected by this issue.
For Revive Adserver versions prior to 3.2.2, update to version 3.2.2 or later.
For CA Release Automation versions prior to 5.0.2-227, update to version 5.0.2-227 or later.
For CA Release Automation versions prior to 5.5.1-1616, update to version 5.5.1-1616 or later.
For CA Release Automation versions prior to 5.5.2-434, update to version 5.5.2-434 or later.
For CA Release Automation versions prior to 6.1.0-1026, update to version 6.1.0-1026 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ca Release Automation
Open Flash Chart 2
Revive Adserver