CVE-2016-10256
Last modified
CVE-2016-10256 is a vulnerability of currently unknown severity. The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This is a separate vulnerability from CVE-2016-10257.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Symantec Proxysg | >= 6.5, < 6.5.10.6 |
| Broadcom | Symantec Proxysg | >= 6.7, < 6.7.2.1 |
| Broadcom | Symantec Proxysg | 6.6 |
References
- http://www.securityfocus.com/bid/102451Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040138Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/102451Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040138Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10256?
How severe is CVE-2016-10256?
How do I fix CVE-2016-10256?
Are you affected by CVE-2016-10256?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
