CVE-2016-1230
UnknownEPSS 1.02%
Last modified
CVE-2016-1230 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ntt | Webarena Service Formmail | <= 2.2.0 |
References
- http://jvn.jp/en/jp/JVN24143619/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000072Vendor Advisory
- http://web.arena.ne.jp/support/news/2016/0208.htmlVendor Advisory
- http://web.arena.ne.jp/support/news/2016/0208_2.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN24143619/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000072Vendor Advisory
- http://web.arena.ne.jp/support/news/2016/0208.htmlVendor Advisory
- http://web.arena.ne.jp/support/news/2016/0208_2.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1230?
Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
How severe is CVE-2016-1230?
Severity scoring for CVE-2016-1230 is pending analysis. The EPSS model estimates a 1.02% probability of exploitation in the next 30 days.
How do I fix CVE-2016-1230?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-1224CRLF injection vulnerability in Trend Micro Worry-Free Busin…6.1
- CVE-2016-1225Trend Micro Internet Security 8 and 10 allows remote attacke…
- CVE-2016-1226Cross-site scripting (XSS) vulnerability in Trend Micro Inte…
- CVE-2016-1227NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400…7.2
- CVE-2016-1228Cross-site request forgery (CSRF) vulnerability on NTT EAST …8.8
- CVE-2016-1229Cross-site scripting (XSS) vulnerability in HumHub 0.20.0-be…
- CVE-2016-1231Directory traversal vulnerability in the HTTP file-serving m…
- CVE-2016-1232The mod_dialback module in Prosody before 0.9.9 does not pro…
- CVE-2016-1233An unspecified udev rule in the Debian fuse package in jessi…
- CVE-2016-1234Stack-based buffer overflow in the glob implementation in GN…
- CVE-2016-1235The oarsh script in OAR before 2.5.7 allows remote authentic…
- CVE-2016-1236Multiple cross-site scripting (XSS) vulnerabilities in (1) r…
Are you affected by CVE-2016-1230?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
