CVE-2016-3969: XSS
Published Apr 6, 2016
·Updated
Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote attackers to inject arbitrary web script or HTML via an attachment in a blocked email.
Affected Software
5 affected components
McAfee Email Gateway=7.6
McAfee Email Gateway=7.6.1
McAfee Email Gateway=7.6.2
McAfee Email Gateway=7.6.3
McAfee Email Gateway=7.6.4
Event History
Apr 6, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3969?
CVE-2016-3969 is classified as a medium severity vulnerability due to its cross-site scripting risk.
2
How do I fix CVE-2016-3969?
To fix CVE-2016-3969, upgrade McAfee Email Gateway to version 7.6.404 or later.
3
What software versions are affected by CVE-2016-3969?
CVE-2016-3969 affects McAfee Email Gateway versions 7.6.x up to 7.6.404.
4
Can CVE-2016-3969 be exploited remotely?
Yes, CVE-2016-3969 allows remote attackers to exploit the vulnerability via a crafted email attachment.
5
What potential impact does CVE-2016-3969 have?
Exploitation of CVE-2016-3969 can lead to arbitrary web script or HTML injection into the user's browser.