First published: Wed Nov 19 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via the refr parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | <=5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8629 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2014-8629, upgrade Pandora FMS to version 5.1 SP2 or later.
CVE-2014-8629 allows attackers to perform cross-site scripting attacks by injecting malicious scripts through the refr parameter.
Pandora FMS versions up to and including 5.1 SP1 are affected by CVE-2014-8629.
CVE-2014-8629 is primarily a client-side vulnerability, as it affects the way web browsers execute scripts from the affected server.