Back to search
CVE-2013-7025
Published: Dec 9, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script or HTML via the (1) valfield_1 or (2) value_1 parameter to createNewThreshold.jsp.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20131205 Sonicwall GMS v7.x - Filter Bypass & Persistent Vulnerability (0Day)
mailing-list
x_refsource_BUGTRAQ
55923
third-party-advisory
x_refsource_SECUNIA
sonicwall-ematstaticalerttypes-xss(89462)
vdb-entry
x_refsource_XF
100610
vdb-entry
x_refsource_OSVDB
20131205 Sonicwall GMS v7.x - Filter Bypass & Persistent Vulnerability
mailing-list
x_refsource_FULLDISC
64103
vdb-entry
x_refsource_BID
1029433
vdb-entry
x_refsource_SECTRACK
30054
exploit
x_refsource_EXPLOIT-DB
http://www.vulnerability-lab.com/get_content.php?id=1099
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now