MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to inject arbitrary web script or HTML via the (1) PROFILENAME parameter in a Save action to httpd/cgi-bin/pppsetup.cgi or (2) COMMENT parameter in an Add action to httpd/cgi-bin/ddns.cgi
Published Dec 31, 2014
4.3
MEDIUMCVSS 2.0
EPSS 1.43%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.