CVE-2014-5121: XSS
Published Aug 22, 2014
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Affected Software
2 affected components
Esri ArcGIS Server=10.1.1
Esri ArcGIS for Server=10.1.1
Event History
Aug 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5121?
CVE-2014-5121 has a moderate severity rating due to its potential for allowing remote attackers to inject malicious scripts.
2
How do I fix CVE-2014-5121?
To fix CVE-2014-5121, upgrade ESRI ArcGIS for Server to the latest version that resolves these cross-site scripting vulnerabilities.
3
What types of attacks are possible with CVE-2014-5121?
CVE-2014-5121 allows for cross-site scripting attacks, which can result in unauthorized access, data theft, or session hijacking.
4
Which versions of ESRI software are affected by CVE-2014-5121?
CVE-2014-5121 specifically affects ESRI ArcGIS for Server version 10.1.1.
5
Is CVE-2014-5121 a local or remote vulnerability?
CVE-2014-5121 is a remote vulnerability that can be exploited by attackers over the internet.