CVE-2015-4665: XSS
Published Aug 13, 2015
·Updated
Cross-site scripting (XSS) vulnerability in ajaxcmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.
Affected Software
2 affected components
Xceedium Xsuite=2.3.0
Xceedium Xsuite=2.4.3.0
Event History
Aug 13, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4665?
CVE-2015-4665 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-4665?
To mitigate CVE-2015-4665, upgrade to a version of Xceedium Xsuite later than 2.4.4.1 that addresses this vulnerability.
3
Which versions of Xceedium Xsuite are affected by CVE-2015-4665?
CVE-2015-4665 affects Xceedium Xsuite versions 2.4.4.1 and earlier, including 2.3.0 and 2.4.3.0.
4
What type of vulnerability is CVE-2015-4665?
CVE-2015-4665 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject web scripts or HTML.
5
Can CVE-2015-4665 be exploited remotely?
Yes, CVE-2015-4665 can be exploited remotely by attackers through the fileName parameter.