CVE-2015-5691
Last modified
CVE-2015-5691 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated an attack against admin_messages.php.. EPSS estimates a 2.17% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated an attack against admin_messages.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Web Gateway | <= 5.2.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5691?
How severe is CVE-2015-5691?
How do I fix CVE-2015-5691?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-5685The lazy_bdecode function in BitTorrent DHT bootstrap server…
- CVE-2015-5686Parts of the Puppet Enterprise Console 3.x were found to be …8.8
- CVE-2015-5687system/session/drivers/cookie.php in Anchor CMS 0.9.x allows…
- CVE-2015-5688Directory traversal vulnerability in lib/app/index.js in Ged…
- CVE-2015-5689ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Sol…
- CVE-2015-5690The management console on Symantec Web Gateway (SWG) applian…
- CVE-2015-5692admin_messages.php in the management console on Symantec Web…
- CVE-2015-5693The management console on Symantec Web Gateway (SWG) applian…
- CVE-2015-5694Designate does not enforce the DNS protocol limit concerning…6.5
- CVE-2015-5695Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStac…
- CVE-2015-5696Dell Netvault Backup before 10.0.5 allows remote attackers t…
- CVE-2015-5697The get_bitmap_file function in drivers/md/md.c in the Linux…
Are you affected by CVE-2015-5691?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
