![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2014-1612 |
Description: | Cross-site scripting (XSS) vulnerability in login.esp in the Web Management Interface in Media5 Mediatrix 4402 VoIP Gateway with firmware Dgw 1.1.13.186 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.103900 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-1612 BugTraq ID: 65108 http://www.securityfocus.com/bid/65108 Bugtraq: 20140123 Reflected cross-site scripting (XSS) vulnerability in Mediatrix Web Management Interface login page (Google Search) http://www.securityfocus.com/archive/1/530871/100/0/threaded CERT/CC vulnerability note: VU#252294 http://www.kb.cert.org/vuls/id/252294 http://packetstormsecurity.com/files/124931/Mediatrix-4402-Cross-Site-Scripting.html http://osvdb.org/102415 http://secunia.com/advisories/56638 XForce ISS Database: mediatrixwebmanagement-cve20141612-xss(90656) https://exchange.xforce.ibmcloud.com/vulnerabilities/90656 |