CVE-2015-3447: XSS
Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3447?
CVE-2015-3447 is rated as a medium-severity vulnerability due to its potential for remote exploitation through cross-site scripting attacks.
How do I fix CVE-2015-3447?
To fix CVE-2015-3447, it is recommended to update Dell SonicWall SonicOS to the latest version available that addresses the XSS vulnerabilities.
What types of attacks are possible with CVE-2015-3447?
CVE-2015-3447 allows attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML into affected applications.
Which versions of SonicOS are affected by CVE-2015-3447?
CVE-2015-3447 affects versions 6.x of SonicOS prior to 6.2.2.0 and specifically version 7.5.0.12.
Can CVE-2015-3447 be exploited remotely?
Yes, CVE-2015-3447 can be exploited remotely by attackers through crafted requests to the vulnerable parameters.