CVE-2014-2879
Last modified
CVE-2014-2879 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page.. EPSS estimates a 4.85% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Email Security Appliance | <= 7.4.5 |
References
- http://seclists.org/fulldisclosure/2014/Mar/409Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/66501Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029965Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2014/Mar/409Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/66501Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029965Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-2879?
How severe is CVE-2014-2879?
How do I fix CVE-2014-2879?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-2870The default configuration of PaperThin CommonSpot before 7.0…
- CVE-2014-2871PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relie…
- CVE-2014-2872PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow…
- CVE-2014-2873PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does …
- CVE-2014-2874PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow…
- CVE-2014-2875The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha …6.1
- CVE-2014-2880Open redirect vulnerability in the Oracle Identity Manager c…
- CVE-2014-2881Unspecified vulnerability in the Diffie-Hellman key agreemen…
- CVE-2014-2882Unspecified vulnerability in the management GUI in Citrix Ne…
- CVE-2014-2884The ProcessVolumeDeviceControlIrp function in Ntdriver.c in …
- CVE-2014-2885Multiple integer overflows in TrueCrypt 7.1a allow local use…
- CVE-2014-2886GKSu 2.0.2, when sudo-mode is not enabled, uses " (double qu…
Are you affected by CVE-2014-2879?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
