CVE-2014-2711
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in J-Web in Juniper Junos before 11.4R11, 11.4X27 before 11.4X27.62 (BBE), 12.1 before 12.1R9, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.2 before 12.2R7, 12.3 before 12.3R6, 13.1 before 13.1R4, 13.2 before 13.2R3, and 13.3 before 13.3R1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Vulnerabilidad de XSS en J-Web en Juniper Junos en versiones anteriores a 11.4R11, 11.4X27 en versiones anteriores a 11.4X27.62 (BBE), 12.1 en versiones anteriores a 12.1R9, 12.1X44 en versiones anteriores a 12.1X44-D35, 12.1X45 en versiones anteriores a 12.1X45-D25, 12.1X46 en versiones anteriores a 12.1X46-D20, 12.2 en versiones anteriores a 12.2R7, 12.3 en versiones anteriores a 12.3R6, 13.1 en versiones anteriores a 13.1R4, 13.2 en versiones anteriores a 13.2R3 y 13.3 en versiones anteriores a 13.3R1 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-04-01 CVE Reserved
- 2014-04-14 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/66770 | Vdb Entry | |
http://www.securitytracker.com/id/1030061 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10619 | 2015-10-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 11.4 Search vendor "Juniper" for product "Junos" and version "11.4" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 11.4x27 Search vendor "Juniper" for product "Junos" and version "11.4x27" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 12.1 Search vendor "Juniper" for product "Junos" and version "12.1" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 12.1x44 Search vendor "Juniper" for product "Junos" and version "12.1x44" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 12.1x45 Search vendor "Juniper" for product "Junos" and version "12.1x45" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 12.1x46 Search vendor "Juniper" for product "Junos" and version "12.1x46" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 12.2 Search vendor "Juniper" for product "Junos" and version "12.2" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 12.3 Search vendor "Juniper" for product "Junos" and version "12.3" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 13.1 Search vendor "Juniper" for product "Junos" and version "13.1" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 13.2 Search vendor "Juniper" for product "Junos" and version "13.2" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Junos Search vendor "Juniper" for product "Junos" | 13.3 Search vendor "Juniper" for product "Junos" and version "13.3" | - |
Affected
|