4.3

CVE-2013-6175

Multiple cross-site scripting (XSS) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote attackers to inject arbitrary web script or HTML via unspecified input to a (1) xAdmin or (2) xDashboard form.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EmcDocument Sciences Xpression Version4.1 Updatesp1 Edition- SwEditiondocumentum
EmcDocument Sciences Xpression Version4.2 Update- Edition- SwEditiondocumentum
EmcDocument Sciences Xpression Version4.5 Update- Edition- SwEditiondocumentum
EmcDocument Sciences Xpression Version4.1 Updatesp1 Edition- SwEditionenterprise SwPlatform- HwPlatform-
EmcDocument Sciences Xpression Version4.2 Update- Edition- SwEditionenterprise SwPlatform- HwPlatform-
EmcDocument Sciences Xpression Version4.5 Update- Edition- SwEditionenterprise SwPlatform- HwPlatform-
EmcDocument Sciences Xpression Version4.1 Updatesp1 Edition- SwEditionenterprise SwPlatform- HwPlatform-
EmcDocument Sciences Xpression Version4.2 Update- Edition- SwEditionenterprise SwPlatform- HwPlatform-
EmcDocument Sciences Xpression Version4.5 Update- Edition- SwEditionenterprise SwPlatform- HwPlatform-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.617
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.