CVE-2013-0688: XSS
Published May 9, 2013
·Updated
Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
3 affected components
Invensys Wonderware Information Server=4.0-sp1sp1
Invensys Wonderware Information Server=4.5
Invensys Wonderware Information Server=5.0
Event History
May 9, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0688?
CVE-2013-0688 has a medium severity rating due to its ability to allow remote attackers to execute arbitrary web scripts or HTML.
2
How do I fix CVE-2013-0688?
To fix CVE-2013-0688, it is recommended to update to a patched version of Invensys Wonderware Information Server provided by the vendor.
3
What versions of Invensys Wonderware Information Server are affected by CVE-2013-0688?
CVE-2013-0688 affects Invensys Wonderware Information Server versions 4.0 SP1 SP1, 4.5 Portal, and 5.0 Portal.
4
What type of vulnerability is CVE-2013-0688?
CVE-2013-0688 is a Cross-site scripting (XSS) vulnerability.
5
Can CVE-2013-0688 be exploited remotely?
Yes, CVE-2013-0688 can be exploited remotely, allowing attackers to inject malicious scripts.