CVE-2014-0953
published 2014-08-12CVE-2014-0953: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.81%
76.2th percentile
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SERVER Generic PHP Remote File Include
suricata·2014-12-17
CVE-2002-0953 ET WEB_SERVER Generic PHP Remote File Include
ET WEB_SERVER Generic PHP Remote File Include
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Generic PHP Remote File Include"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"allow_url_include"; http.uri.raw; content:"php|3a 2f 2f|input"; http.request_body; content:"<?php"; fast_pattern; reference:cve,2002-0953; reference:cve,2024-4577; classtype:attempted-user; sid:2019957; rev:6; metadata:affected_product Any, attack_target Server, created_at 2014_12_17, deployment Datacenter, confidence High, signature_severity Major, tag Remote_File_Include, updated_at 2024_06_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1PI16127http://www-01.ibm.com/support/docview.wss?uid=swg21680230http://www.securitytracker.com/id/1030669https://exchange.xforce.ibmcloud.com/vulnerabilities/92626http://www-01.ibm.com/support/docview.wss?uid=swg1PI16127http://www-01.ibm.com/support/docview.wss?uid=swg21680230http://www.securitytracker.com/id/1030669https://exchange.xforce.ibmcloud.com/vulnerabilities/92626
2014-08-12
Published