CVE-2014-8911
published 2015-02-14CVE-2014-8911: Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.0 and 2.0.1 before 2.0.1.2 FP002 IF003 and 2.0.3 before 2.0.3.2 FP002 allows remote…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.93%
56.5th percentile
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.0 and 2.0.1 before 2.0.1.2 FP002 IF003 and 2.0.3 before 2.0.3.2 FP002 allows remote attackers to inject arbitrary web script or HTML via the Accept-Language HTTP header.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | content_navigator | — | — |
| ibm | content_navigator | — | — |
| ibm | content_navigator | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Netgear passwordrecovered.cgi attempt
suricata·2014-01-15
CVE-2017-5521 ET EXPLOIT Netgear passwordrecovered.cgi attempt
ET EXPLOIT Netgear passwordrecovered.cgi attempt
Rule: alert http any any -> any any (msg:"ET EXPLOIT Netgear passwordrecovered.cgi attempt"; flow:established,to_server; http.method; content:"POST"; nocase; http.uri; content:"/passwordrecovered.cgi?id="; nocase; reference:url,www.securityfocus.com/archive/1/530743/30/0/threaded; reference:url,www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-003/?fid=8911; reference:cve,2017-5521; classtype:attempted-admin; sid:2017969; rev:6; metadata:created_at 2014_01_15, cve CVE_2017_5521, signature_severity Major, updated_at 2024_03_06;)
No public exploits indexed.
No writeups or analysis indexed.
2015-02-14
Published