CVE-2015-7679: XSS
Published Feb 10, 2016
·Updated
Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/.
Affected Software
1 affected component
IPSwitch MOVEit Mobile<=1.2.0.962
Event History
Feb 10, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7679?
CVE-2015-7679 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2015-7679?
To fix CVE-2015-7679, upgrade to Ipswitch MOVEit Mobile version 1.2.2 or later.
3
What versions are affected by CVE-2015-7679?
CVE-2015-7679 affects all versions of Ipswitch MOVEit Mobile prior to 1.2.2.
4
Can CVE-2015-7679 be exploited remotely?
Yes, CVE-2015-7679 can be exploited remotely by sending specially crafted query strings to the application.
5
What type of attack does CVE-2015-7679 enable?
CVE-2015-7679 enables remote attackers to execute arbitrary web scripts or HTML on affected systems.