CVE-2013-5664

Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
paloaltonetworkspan-os
4.0.0
paloaltonetworkspan-os
4.0.1
paloaltonetworkspan-os
4.0.2
paloaltonetworkspan-os
4.0.3
paloaltonetworkspan-os
4.0.4
paloaltonetworkspan-os
4.0.5
paloaltonetworkspan-os
4.0.6
paloaltonetworkspan-os
4.0.7
paloaltonetworkspan-os
4.0.8
paloaltonetworkspan-os
4.1.0
paloaltonetworkspan-os
4.1.1
paloaltonetworkspan-os
4.1.2
paloaltonetworkspan-os
4.1.3
paloaltonetworkspan-os
4.1.4
paloaltonetworkspan-os
4.1.5
paloaltonetworkspan-os
4.1.6
paloaltonetworkspan-os
4.1.7
paloaltonetworkspan-os
4.1.8
paloaltonetworkspan-os
4.1.8-h3
paloaltonetworkspan-os
4.1.9
paloaltonetworkspan-os
4.1.10
paloaltonetworkspan-os
4.1.11
paloaltonetworkspan-os
4.1.12
paloaltonetworkspan-os
5.0.0
paloaltonetworkspan-os
5.0.0-h1
paloaltonetworkspan-os
5.0.2
paloaltonetworkspan-os
5.0.3
paloaltonetworkspan-os
5.0.4
paloaltonetworkspan-os
5.0.5
𝑥
= Vulnerable software versions