First published: Tue Oct 21 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenable Web UI | <=2.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7280 is classified as a medium severity vulnerability.
To fix CVE-2014-7280, you should upgrade the Tenable Web UI to version 2.3.4 Build #85 or later.
CVE-2014-7280 is a cross-site scripting (XSS) vulnerability.
Versions of Tenable Nessus Web UI before 2.3.4 Build #85 are affected by CVE-2014-7280.
Attackers can inject arbitrary web script or HTML via the server header due to CVE-2014-7280.