Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-2026

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2014-2026
Last Modified 10 Feb 2015 01:03:53
Published 19 Dec 2014 10:59:03
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2014-2026

Summary

Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Vulnerable Systems

Application

  • Unitedplanet Intrexx 5.2

  • Unitedplanet Intrexx 6.0

  • Unitedplanet Intrexx Professional 5.2

  • Unitedplanet Intrexx Professional 6.0


References

CONFIRM - https://help.unitedplanet.com/?rq_AppGuid=C203A277EDDF9AD2492B776B996B20D4A7C58395&rq_TargetPageGuid=2EBBF802B1970FE31EFC8A34108DF3F47E7A8EEC&rq_RecId=32&rq_SourceAppGuid=C203A277EDDF9AD2492B776B996B20D4A7C58395&rq_SourcePageGuid=7A91F4B76FFC41A18F4EA4ACE26F31E033C5B018&rq_SourceRecId=32

BID - 71673

BUGTRAQ - 20141214 CVE-2014-2026 Reflected Cross-Site Scripting (XSS) in "Intrexx Professional"

MISC - http://www.christian-schneider.net/advisories/CVE-2014-2026.txt

MISC - http://packetstormsecurity.com/files/129590/Intrexx-Professional-6.0-5.2-Cross-Site-Scripting.html


Last Updated: 27 May 2016 11:07:44