CVE-2013-2643 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action to rss.php (2) msg parameter to end-user/errdoc.php (3) h parameter to end-user/ftp_redirect.php or (4) threat parameter to the Blocked component.
Reference
http://www.sophos.com/en-us/support/knowledgebase/118969.aspx https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20130403-0_Sophos_Web_Protection_Appliance_Multiple_Vulnerabilities.txt
Share on: