CVE-2016-6204

Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:55

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/92114 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/92114 - Third Party Advisory, VDB Entry
References () http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-119132.pdf - Mitigation, Vendor Advisory () http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-119132.pdf - Mitigation, Vendor Advisory
References () https://ics-cert.us-cert.gov/advisories/ICSA-16-208-03 - () https://ics-cert.us-cert.gov/advisories/ICSA-16-208-03 -

Information

Published : 2016-07-22 15:59

Updated : 2024-11-21 02:55


NVD link : CVE-2016-6204

Mitre link : CVE-2016-6204

CVE.ORG link : CVE-2016-6204


JSON object : View

Products Affected

siemens

  • sinema_remote_connect_server
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')