CVE-2014-0338: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the polname parameter.
Affected Software
Event History
Frequently Asked Questions
What are the common symptoms of CVE-2014-0338?
Common symptoms include unexpected behavior in firewall policy management pages and potential unauthorized script execution.
How do I fix CVE-2014-0338?
To address CVE-2014-0338, upgrade WatchGuard Fireware to version 11.8.3 or later.
Is CVE-2014-0338 a critical vulnerability?
CVE-2014-0338 is classified as a medium severity vulnerability due to its potential for exploiting cross-site scripting.
What software versions are affected by CVE-2014-0338?
CVE-2014-0338 affects WatchGuard Fireware versions prior to 11.8.3, including 11.6.x and 11.7.x series.
Can CVE-2014-0338 be exploited remotely?
Yes, CVE-2014-0338 can be exploited remotely by attackers injecting malicious scripts through the pol_name parameter.