CVE-2016-5061: XSS
Published Sep 29, 2016
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the web server in Aternity before 9.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTPAgent, (2) MacAgent, (3) getExternalURL, or (4) retrieveTrustedUrl page.
Affected Software
1 affected component
Aternity Aternity<=9.0
Event History
Sep 29, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5061?
CVE-2016-5061 has been classified with a medium severity due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2016-5061?
To mitigate CVE-2016-5061, upgrade your Aternity software to version 9.0.1 or later.
3
What platforms are affected by CVE-2016-5061?
CVE-2016-5061 affects all versions of Aternity prior to 9.0.1.
4
What types of attacks can CVE-2016-5061 enable?
CVE-2016-5061 can enable remote attackers to execute arbitrary web scripts or HTML through cross-site scripting techniques.
5
Are there any known exploits for CVE-2016-5061?
Yes, there are publicly reported methods to exploit CVE-2016-5061 to perform XSS attacks on vulnerable Aternity instances.