First published: Tue Jul 22 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter to exclusion/configure or (4) text:EmailServer or (5) newListList:Email parameter to notification/configure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Anti-Virus Linux kernel | <=9.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The consequences of CVE-2014-2385 include the potential for local users to execute arbitrary web scripts or HTML within the Sophos Anti-Virus web UI.
To remediate CVE-2014-2385, upgrading Sophos Anti-Virus for Linux to version 9.6.1 or later is recommended to eliminate these vulnerabilities.
CVE-2014-2385 affects Sophos Anti-Virus for Linux versions prior to 9.6.1.
Local users of Sophos Anti-Virus for Linux versions prior to 9.6.1 are primarily affected by CVE-2014-2385.
CVE-2014-2385 is classified as a cross-site scripting (XSS) vulnerability.