Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.140301
Kategorie:Web application abuses
Titel:Biscom Secure File Transfer XSS Vulnerability
Zusammenfassung:Biscom Secure File Transfer is prone to a cross-site scripting;vulnerability.
Beschreibung:Summary:
Biscom Secure File Transfer is prone to a cross-site scripting
vulnerability.

Vulnerability Insight:
The Workspaces component of Biscom Secure File Transfer (SFT) is vulnerable
to stored cross-site scripting in two fields. An attacker would need to have the ability to create a Workspace
and entice a victim to visit the malicious page in order to run malicious Javascript in the context of the
victim's browser. Since the victim is necessarily authenticated, this can allow the attacker to perform actions
on the Biscom Secure File Transfer instance on the victim's behalf.

Affected Software/OS:
Synology Photo Station before 5.1.1025.

Solution:
Update to version 5.1.1025 or later.

CVSS Score:
3.5

CVSS Vector:
AV:N/AC:M/Au:S/C:N/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-5241
BugTraq ID: 99341
http://www.securityfocus.com/bid/99341
https://community.rapid7.com/community/infosec/blog/2017/06/27/r7-2017-06-biscom-sftp-xss-cve-2017-5241
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.