CVE-2017-3961 – SB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2017-3961
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attributes. Vulnerabilidad de Cross-Site Scripting (XSS) en la interfaz web en McAfee Network Security Management (NSM) en versiones anteriores a la 8.2.7.42.2 permite que usuarios autenticados puedan reflejar código HTML arbitrario en la página web de respuesta mediante entradas de atributos de usuarios que hayan sido manipuladas. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-3964 – SB10192 - Network Security Management (NSM) - Reflective Cross-Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2017-3964
Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a URL parameter. Vulnerabilidad de Cross-Site Scripting (XSS) reflejado en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes inyecten scripts web o HTML arbitrarios mediante un parámetro URL. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-3966 – SB10192 - Network Security Management (NSM) - Exploitation of session variables, resource IDs and other trusted credentials vulnerability
https://notcve.org/view.php?id=CVE-2017-3966
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL. Vulnerabilidad de explotación de variables de sesión, ID de los recursos y otras credenciales de confianza en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes remotos exploten o dañen el navegador de un usuario reutilizando el token de sesión expuesto en la URL de la aplicación. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-613: Insufficient Session Expiration •
CVE-2017-3971 – SB10192 - Network Security Management (NSM) - Cryptanalysis vulnerability
https://notcve.org/view.php?id=CVE-2017-3971
Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers. Vulnerabilidad de criptoanálisis en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes vean información confidencial mediante el uso inseguro de un cypher de cifrado RC4. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-326: Inadequate Encryption Strength •
CVE-2017-3965 – SB10192 - Network Security Management (NSM) - Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability
https://notcve.org/view.php?id=CVE-2017-3965
Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs. Vulnerabilidad de Cross-Site Request Forgery (CSRF), también conocido como Session Riding, en la interfaz web de Session Riding en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes remotos realicen tareas no autorizadas como la recuperación de información interna del sistema o la manipulación de la base de datos mediante URL especialmente manipuladas. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-352: Cross-Site Request Forgery (CSRF) •