Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mq86-6vpq-5qff

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.

Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.

EPSS

Процентиль: 67%
0.00534
Низкий

Связанные уязвимости

nvd
почти 22 года назад

Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.

EPSS

Процентиль: 67%
0.00534
Низкий