cbcvebase.
CVE-2018-0059
published 2018-10-10

CVE-2018-0059: A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML…

medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos