Sploitus

CVE-2014-0338

1 known exploit for CVE-2014-0338

Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the pol_name parameter.

Affected products
Watchguard Fireware
Watchguard Fireware
≤ 11.8.1, 11.6, 11.6.1, 11.6.3, 11.6.5, 11.6.6, 11.7, 11.7.2, 11.7.3, 11.7.4, 11.8
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
1.6% (74th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2014-03-16
CVE-2014-0338 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2014-0338

Proof-of-concept code and exploit modules indexed by Sploitus