CVE-2013-2643: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action to rss.php, (2) msg parameter to end-user/errdoc.php, (3) h parameter to end-user/ftpredirect.php, or (4) threat parameter to the Blocked component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2643?
CVE-2013-2643 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-2643?
To fix CVE-2013-2643, update the Sophos Web Appliance to version 3.7.8.2 or later.
What types of vulnerabilities are present in CVE-2013-2643?
CVE-2013-2643 contains multiple cross-site scripting (XSS) vulnerabilities.
Who is affected by CVE-2013-2643?
CVE-2013-2643 affects versions of Sophos Web Appliance firmware prior to 3.7.8.2.
What attack vector does CVE-2013-2643 use?
CVE-2013-2643 can be exploited through the injection of arbitrary web scripts or HTML via specific parameters in the application.