4.3

CVE-2013-4674

Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted encrypted e-mail attachment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Encryption Management Server Update mp1 Version <= 3.3.0
Symantec ≫ Pgp Universal Server Version 3.2.0
Symantec ≫ Pgp Universal Server Version 3.2.1
Symantec ≫ Pgp Universal Server Version 3.2.1 Update mp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.89% 0.545
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://osvdb.org/95581
http://secunia.com/advisories/54214
http://www.securityfocus.com/bid/61290
http://www.securitytracker.com/id/1028820
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130722_00
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/85902