Sploitus

CVE-2014-1648

1 known exploit for CVE-2014-1648

Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary web script or HTML via the displayTab parameter.

Symantec Messaging Gateway
= 10.0, 10.0.1, 10.0.2, 10.0.3, 10.5.0, 10.5.1
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
2.1% (80th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2014-04-23
CVE-2014-1648 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2014-1648

Proof-of-concept code and exploit modules indexed by Sploitus