CVE-2014-1648
23.04.2014, 11:52
Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary web script or HTML via the displayTab parameter.
Vendor | Product | Version |
---|---|---|
symantec | messaging_gateway | 10.0 |
symantec | messaging_gateway | 10.0.1 |
symantec | messaging_gateway | 10.0.2 |
symantec | messaging_gateway | 10.0.3 |
symantec | messaging_gateway | 10.5.0 |
symantec | messaging_gateway | 10.5.1 |
𝑥
= Vulnerable software versions
References