CVE-2014-9429: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to inject arbitrary web script or HTML via the (1) PROFILENAME parameter in a Save action to httpd/cgi-bin/pppsetup.cgi or (2) COMMENT parameter in an Add action to httpd/cgi-bin/ddns.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9429?
CVE-2014-9429 is considered to be of medium severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-9429?
To fix CVE-2014-9429, apply the latest patches provided by Smoothwall for versions 3.0 SP3 and 3.1.
What systems are affected by CVE-2014-9429?
CVE-2014-9429 affects Smoothwall Express versions 3.0 SP3 and 3.1.
What are the attack vectors for CVE-2014-9429?
Attackers can exploit CVE-2014-9429 through the PROFILENAME and COMMENT parameters in specific CGI scripts.
Can CVE-2014-9429 lead to data leakage?
Yes, exploitation of CVE-2014-9429 could allow attackers to inject arbitrary scripts, potentially leading to data leakage.