VulnerabilityModified
CVE-2007-5796
Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate…
MEDIUM 4.3EPSS 2.35%
Does this matter?
Lower severity and a low EPSS score (2.35%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revocation Lists.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.35% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- symantec/proxysg firmware
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/27452Third Party Advisory
- http://www.bluecoat.com/support/securityadvisories/advisory_cross-site_scripting_vulnerabilityPatch, Vendor Advisory
- http://www.securitytracker.com/id?1018888Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3678Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38213Third Party Advisory, VDB Entry
- http://secunia.com/advisories/27452Third Party Advisory
- http://www.bluecoat.com/support/securityadvisories/advisory_cross-site_scripting_vulnerabilityPatch, Vendor Advisory
- http://www.securitytracker.com/id?1018888Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3678Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38213Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.