CVE-2016-4847: XSS
Published Apr 20, 2017
·Updated
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex.
Affected Software
1 affected component
OSSEC Web UI<=0.8
Remediation
Event History
Apr 20, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4847?
CVE-2016-4847 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2016-4847?
To fix CVE-2016-4847, update the OSSEC Web UI to version 0.9 or later.
3
What kind of attack does CVE-2016-4847 enable?
CVE-2016-4847 enables remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
4
Which versions of OSSEC are affected by CVE-2016-4847?
CVE-2016-4847 affects the OSSEC Web UI versions prior to 0.9.
5
Where can I find more information about CVE-2016-4847?
For more detailed information, refer to the official CVE database or vulnerability advisory sites.