First published: Tue May 24 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bluecoat Reporter | <=7.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1710 is classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-1710, upgrade Blue Coat Reporter to version 7.1.2 or later.
CVE-2005-1710 enables remote attackers to conduct cross-site scripting attacks through the username and license key inputs.
CVE-2005-1710 affects Blue Coat Reporter versions prior to 7.1.2, specifically up to version 7.1.1.
CVE-2005-1710 can be exploited by remote attackers with access to the affected Blue Coat Reporter web interface.