CVE-2018-0059
10.10.2018, 18:29
A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.
Vendor | Product | Version |
---|---|---|
juniper | netscreen_screenos | 6.3.0 |
juniper | netscreen_screenos | 6.3.0r1:r1 |
juniper | netscreen_screenos | 6.3.0r2:r2 |
juniper | netscreen_screenos | 6.3.0r3:r3 |
juniper | netscreen_screenos | 6.3.0r4:r4 |
juniper | netscreen_screenos | 6.3.0r5:r5 |
juniper | netscreen_screenos | 6.3.0r6:r6 |
juniper | netscreen_screenos | 6.3.0r7:r7 |
juniper | netscreen_screenos | 6.3.0r8:r8 |
juniper | netscreen_screenos | 6.3.0r9:r9 |
juniper | netscreen_screenos | 6.3.0r10:r10 |
juniper | netscreen_screenos | 6.3.0r11:r11 |
juniper | netscreen_screenos | 6.3.0r12:r12 |
juniper | netscreen_screenos | 6.3.0r13:r13 |
juniper | netscreen_screenos | 6.3.0r14:r14 |
juniper | netscreen_screenos | 6.3.0r15:r15 |
juniper | netscreen_screenos | 6.3.0r16:r16 |
juniper | netscreen_screenos | 6.3.0r17:r17 |
juniper | netscreen_screenos | 6.3.0r18:r18 |
juniper | netscreen_screenos | 6.3.0r19:r19 |
juniper | netscreen_screenos | 6.3.0r21:r21 |
juniper | netscreen_screenos | 6.3.0r22:r22 |
juniper | netscreen_screenos | 6.3.0r23:r23 |
juniper | netscreen_screenos | 6.3.0r23b1:r23b1 |
juniper | netscreen_screenos | 6.3.0r24:r24 |
juniper | netscreen_screenos | 6.3.0r24b1:r24b1 |
juniper | netscreen_screenos | 6.3.0r25:r25 |
𝑥
= Vulnerable software versions