First published: Thu Jan 31 2019(Updated: )
servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XSS] in the query string. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. NOTE: this product is discontinued.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Enterprise Server | =3.63 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18940 is classified as a high severity vulnerability due to the potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2018-18940, it is recommended to update to a patched version of Netscape Enterprise Server or disable the vulnerable SnoopServlet functionality.
CVE-2018-18940 affects users of Netscape Enterprise Server version 3.63 that have the SnoopServlet installed.
CVE-2018-18940 is a reflected cross-site scripting (XSS) vulnerability that allows the injection of malicious scripts into a web application.
Yes, CVE-2018-18940 can be exploited remotely by an unauthenticated attacker through crafted query parameters.