First published: Tue Aug 19 2014(Updated: )
Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Riverbed Steelapp Traffic Manager | =9.6-9620140312 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5348 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2014-5348, it is recommended to upgrade to a patched version of Riverbed SteelApp Traffic Manager beyond 9.6 patchlevel 9620140312.
Exploiting CVE-2014-5348 allows attackers to inject arbitrary web scripts or HTML, potentially compromising user sessions or defacing web content.
CVE-2014-5348 affects Riverbed SteelApp Traffic Manager version 9.6 patchlevel 9620140312.
CVE-2014-5348 is specifically associated with Riverbed SteelApp Traffic Manager 9.6 and does not affect other versions.