CVE-2018-18940: XSS
servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XSS] in the query string. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. NOTE: this product is discontinued.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18940?
CVE-2018-18940 is classified as a high severity vulnerability due to the potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2018-18940?
To fix CVE-2018-18940, it is recommended to update to a patched version of Netscape Enterprise Server or disable the vulnerable SnoopServlet functionality.
Who is affected by CVE-2018-18940?
CVE-2018-18940 affects users of Netscape Enterprise Server version 3.63 that have the SnoopServlet installed.
What type of vulnerability is CVE-2018-18940?
CVE-2018-18940 is a reflected cross-site scripting (XSS) vulnerability that allows the injection of malicious scripts into a web application.
Can CVE-2018-18940 be exploited remotely?
Yes, CVE-2018-18940 can be exploited remotely by an unauthenticated attacker through crafted query parameters.