First published: Wed Apr 29 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SonicOS | >=6.0.0.0<=6.2.2.0 | |
SonicWall SonicOS | =7.5.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3447 is rated as a medium-severity vulnerability due to its potential for remote exploitation through cross-site scripting attacks.
To fix CVE-2015-3447, it is recommended to update Dell SonicWall SonicOS to the latest version available that addresses the XSS vulnerabilities.
CVE-2015-3447 allows attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML into affected applications.
CVE-2015-3447 affects versions 6.x of SonicOS prior to 6.2.2.0 and specifically version 7.5.0.12.
Yes, CVE-2015-3447 can be exploited remotely by attackers through crafted requests to the vulnerable parameters.