CVE-2014-1648
Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary web script or HTML via the displayTab parameter.
- Affected products
- Symantec Messaging Gateway
- Symantec Messaging Gateway
- = 10.0, 10.0.1, 10.0.2, 10.0.3, 10.5.0, 10.5.1
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2014-04-23
CVE-2014-1648 at NVD
1 known exploit for CVE-2014-1648
Proof-of-concept code and exploit modules indexed by Sploitus