CVE-2017-3961 – SB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2017-3961
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attributes. Vulnerabilidad de Cross-Site Scripting (XSS) en la interfaz web en McAfee Network Security Management (NSM) en versiones anteriores a la 8.2.7.42.2 permite que usuarios autenticados puedan reflejar código HTML arbitrario en la página web de respuesta mediante entradas de atributos de usuarios que hayan sido manipuladas. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-3964 – SB10192 - Network Security Management (NSM) - Reflective Cross-Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2017-3964
Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a URL parameter. Vulnerabilidad de Cross-Site Scripting (XSS) reflejado en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes inyecten scripts web o HTML arbitrarios mediante un parámetro URL. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-3965 – SB10192 - Network Security Management (NSM) - Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability
https://notcve.org/view.php?id=CVE-2017-3965
Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs. Vulnerabilidad de Cross-Site Request Forgery (CSRF), también conocido como Session Riding, en la interfaz web de Session Riding en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes remotos realicen tareas no autorizadas como la recuperación de información interna del sistema o la manipulación de la base de datos mediante URL especialmente manipuladas. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2017-3967 – SB10192 - Network Security Management (NSM) - Target influence via framing vulnerability
https://notcve.org/view.php?id=CVE-2017-3967
Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames. Vulnerabilidad de influencia de objetivo mediante framing en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes remotos inyecten scripts web o HTML arbitrarios aprovechándose de la incapacidad de las páginas de aplicación de liberarse de los frames HTML de terceros. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2017-3969 – SB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerability
https://notcve.org/view.php?id=CVE-2017-3969
Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL. Vulnerabilidad de abuso de canales de comunicación en el servidor en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes Man-in-the-Middle (MitM) descifren mensajes mediante la implementación inadecuada de SSL. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-417: Communication Channel Errors •