Skip to content

CVE-2014-5348

Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0022 (0.2%)
Percentil: 45.1%
EPSS: 2026-05-06

Afecta

riverbed:steelapp_traffic_manager

Descripción técnica

Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.

Publicada: 19/8/2014, 19:55:04
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo