CVE-2008-1463
Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbitrary web script or HTML via an invalid or prohibited request to a web server protected by…
Does this matter?
Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbitrary web script or HTML via an invalid or prohibited request to a web server protected by SecureSphere, which triggers injection into the "corrective action" section of an alert page.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- imperva/securesphere · imperva/securesphere mx management server
- Source
- cve@mitre.org
References
- http://imperva.com/go/secadv/20080318
- http://secunia.com/advisories/29439Vendor Advisory
- http://www.securityfocus.com/bid/28279Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41359
- http://imperva.com/go/secadv/20080318
- http://secunia.com/advisories/29439Vendor Advisory
- http://www.securityfocus.com/bid/28279Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41359
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.