CVE-2014-2589

Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:h:sonicwall:nsa_2400:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:06

Type Values Removed Values Added
References () http://secunia.com/advisories/57275 - Vendor Advisory () http://secunia.com/advisories/57275 - Vendor Advisory
References () http://www.osvdb.org/104089 - Broken Link () http://www.osvdb.org/104089 - Broken Link
References () http://www.securityfocus.com/archive/1/531364/100/0/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/531364/100/0/threaded - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/66042 - Exploit, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/66042 - Exploit, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1029884 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1029884 - Third Party Advisory, VDB Entry
References () http://www.vulnerability-lab.com/get_content.php?id=1100 - Exploit, Third Party Advisory () http://www.vulnerability-lab.com/get_content.php?id=1100 - Exploit, Third Party Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/91766 - VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/91766 - VDB Entry

Information

Published : 2014-03-24 16:39

Updated : 2024-11-21 02:06


NVD link : CVE-2014-2589

Mitre link : CVE-2014-2589

CVE.ORG link : CVE-2014-2589


JSON object : View

Products Affected

sonicwall

  • nsa_2400
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')