Multiple cross-site scripting (XSS) vulnerabilities in the web UI in...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter to exclusion/configure or (4) text:EmailServer or (5) newListList:Email parameter to notification/configure.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-2385
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/532558/100/0/threaded
- http://packetstormsecurity.com/files/127228/Sophos-Antivirus-9.5.1-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2014/Jun/126
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2385/
- http://www.sophos.com/en-us/support/knowledgebase/121135.aspx
- http://www.securitytracker.com/id/1030467
More from sophos
View All →Affected Vendor
sophos
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.