Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
References
Link | Resource |
---|---|
http://files.trendmicro.com/products/officescan/11.0_SP1/readme/osce-11-sp1-patch1-win-all-criticalpatch-6325_readme.txt | Release Notes Vendor Advisory |
https://success.trendmicro.com/solution/1117204-security-bulletin-trend-micro-officescan-11-xg-multiple-vulnerabilities | Mitigation Vendor Advisory |
http://files.trendmicro.com/products/officescan/11.0_SP1/readme/osce-11-sp1-patch1-win-all-criticalpatch-6325_readme.txt | Release Notes Vendor Advisory |
https://success.trendmicro.com/solution/1117204-security-bulletin-trend-micro-officescan-11-xg-multiple-vulnerabilities | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:34
Type | Values Removed | Values Added |
---|---|---|
References | () http://files.trendmicro.com/products/officescan/11.0_SP1/readme/osce-11-sp1-patch1-win-all-criticalpatch-6325_readme.txt - Release Notes, Vendor Advisory | |
References | () https://success.trendmicro.com/solution/1117204-security-bulletin-trend-micro-officescan-11-xg-multiple-vulnerabilities - Mitigation, Vendor Advisory |
Information
Published : 2017-05-05 19:29
Updated : 2024-11-21 03:34
NVD link : CVE-2017-8801
Mitre link : CVE-2017-8801
CVE.ORG link : CVE-2017-8801
JSON object : View
Products Affected
trendmicro
- officescan
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')