Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Web Ui | <= 2.3.3 |
Related Weaknesses (CWE)
References
- http://osvdb.org/112728
- http://packetstormsecurity.com/files/128579/Nessus-Web-UI-2.3.3-Cross-Site-ScripExploit
- http://seclists.org/fulldisclosure/2014/Oct/26Exploit
- http://www.exploit-db.com/exploits/34929Exploit
- http://www.securityfocus.com/bid/70274Exploit
- http://www.tenable.com/security/tns-2014-08Vendor Advisory
- http://www.thesecurityfactory.be/permalink/nessus-stored-xss.htmlExploit
- http://osvdb.org/112728
- http://packetstormsecurity.com/files/128579/Nessus-Web-UI-2.3.3-Cross-Site-ScripExploit
- http://seclists.org/fulldisclosure/2014/Oct/26Exploit
- http://www.exploit-db.com/exploits/34929Exploit
- http://www.securityfocus.com/bid/70274Exploit
- http://www.tenable.com/security/tns-2014-08Vendor Advisory
- http://www.thesecurityfactory.be/permalink/nessus-stored-xss.htmlExploit
FAQ
What is CVE-2014-7280?
CVE-2014-7280 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.
How severe is CVE-2014-7280?
CVE-2014-7280 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-7280?
Check the references section above for vendor advisories and patch information. Affected products include: Tenable Web Ui.