First published: Fri Jul 30 2010(Updated: )
Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nessus Web Server plugin | =1.2.4 | |
Tenable Nessus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2914 is classified as a High severity vulnerability due to its potential for exploitation through cross-site scripting.
To mitigate CVE-2010-2914, you should update the Nessus Web Server plugin to version 1.2.5 or later.
CVE-2010-2914 can enable remote attackers to execute arbitrary web scripts or HTML in the context of the user's session.
CVE-2010-2914 specifically affects Nessus Web Server plugin version 1.2.4.
No, after applying the recommended patch or updating the plugin, CVE-2010-2914 should no longer be exploitable.