CVE-2013-1614
https://notcve.org/view.php?id=CVE-2013-1614
Multiple cross-site scripting (XSS) vulnerabilities in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados en la consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos ejecutar comandos web o HTML mediante vectores no especificados. • http://www.securityfocus.com/bid/60797 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1615
https://notcve.org/view.php?id=CVE-2013-1615
The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote attackers to obtain sensitive information via unspecified web-GUI API calls. La consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos a obtener información sensible a través de llamadas a la API web-GUI no especificadas. • http://www.securityfocus.com/bid/60798 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2013-1613
https://notcve.org/view.php?id=CVE-2013-1613
SQL injection vulnerability in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos ejecutar comandos SQL a través de vectores no especificados. • http://www.securityfocus.com/bid/60796 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •