First published: Fri Aug 22 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ESRI ArcGIS for Server | =10.1.1 | |
Esri ArcGIS Server | =10.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5121 has a moderate severity rating due to its potential for allowing remote attackers to inject malicious scripts.
To fix CVE-2014-5121, upgrade ESRI ArcGIS for Server to the latest version that resolves these cross-site scripting vulnerabilities.
CVE-2014-5121 allows for cross-site scripting attacks, which can result in unauthorized access, data theft, or session hijacking.
CVE-2014-5121 specifically affects ESRI ArcGIS for Server version 10.1.1.
CVE-2014-5121 is a remote vulnerability that can be exploited by attackers over the internet.