Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-5071

Опубликовано: 08 янв. 2018
Источник: nvd
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inject malicious JavaScript code using the device's TELNET shell built-in commands, as demonstrated by the "set ship name" command. This is similar to a Cross Protocol Injection with SNMP.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cobham:sea_tel_116_firmware:222429:*:*:*:*:*:*:*
cpe:2.3:h:cobham:sea_tel_116:-:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00158
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 3 лет назад

Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inject malicious JavaScript code using the device's TELNET shell built-in commands, as demonstrated by the "set ship name" command. This is similar to a Cross Protocol Injection with SNMP.

EPSS

Процентиль: 37%
0.00158
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79