CVE-2017-5870
Last modified
CVE-2017-5870 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter to domain/add; the (3) name parameter to mailbox/add/did/<domain id>; the (4) goto parameter to alias/add/did/<domain id>; or the (5) captchatext parameter to auth/lost-password.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter to domain/add; the (3) name parameter to mailbox/add/did/<domain id>; the (4) goto parameter to alias/add/did/<domain id>; or the (5) captchatext parameter to auth/lost-password.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vimbadmin | Vimbadmin | 3.0.15 |
References
- http://www.openwall.com/lists/oss-security/2017/05/03/8Exploit, Mailing List, Third Party Advisory
- https://sysdream.com/news/lab/2017-05-03-cve-2017-5870-multiple-xss-vulnerabilities-in-vimbadmin/Exploit, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/05/03/8Exploit, Mailing List, Third Party Advisory
- https://sysdream.com/news/lab/2017-05-03-cve-2017-5870-multiple-xss-vulnerabilities-in-vimbadmin/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5870?
How severe is CVE-2017-5870?
How do I fix CVE-2017-5870?
Are you affected by CVE-2017-5870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
