First published: Sun Aug 23 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allow remote attackers to inject arbitrary web script or HTML via (1) crafted input to index.php that is processed by certain Internet Explorer 7 configurations or (2) crafted input to the widget feature.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Deep Discovery Inspector | =3.5 | |
Trendmicro Deep Discovery Inspector | =3.5 | |
Trendmicro Deep Discovery Inspector | =3.5 | |
Trendmicro Deep Discovery Inspector | =3.6 | |
Trendmicro Deep Discovery Inspector | =3.7 | |
Trendmicro Deep Discovery Inspector | =3.7 | |
Trendmicro Deep Discovery Inspector | =3.7 | |
Trendmicro Deep Discovery Inspector | =3.8 | |
Trendmicro Deep Discovery Inspector | =3.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.