CVE-2015-2702
 
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site scripting (XSS) vulnerability in the Message Log in the Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 and V-Series 7.7 appliances allows remote attackers to inject arbitrary web script or HTML via the sender address in an email.
Vulnerabilidad de XSS en el registro de mensajes en el componente Email Security Gateway en Websense TRITON AP-EMAIL anterior a 8.0.0 y las aplicaciones de la serie V 7.7 permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de la dirección de envío en un email.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2015-03-25 CVE Reserved
- 2015-03-25 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2024-11-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/130898/Websense-Email-Security-Cross-Site-Scripting.html | X_refsource_misc | |
http://seclists.org/fulldisclosure/2015/Mar/103 | Mailing List | |
http://www.securityfocus.com/archive/1/534909/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/73345 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.securify.nl/advisory/SFY20140905/websense_email_security_vulnerable_to_persistent_cross_site_scripting_in_audit_log_details_view.html | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Websense Search vendor "Websense" | Triton Ap Data Search vendor "Websense" for product "Triton Ap Data" | <= 7.8.3 Search vendor "Websense" for product "Triton Ap Data" and version " <= 7.8.3" | - |
Affected
| ||||||
Websense Search vendor "Websense" | Triton Ap Email Search vendor "Websense" for product "Triton Ap Email" | <= 7.8.3 Search vendor "Websense" for product "Triton Ap Email" and version " <= 7.8.3" | - |
Affected
| ||||||
Websense Search vendor "Websense" | Triton Ap Web Search vendor "Websense" for product "Triton Ap Web" | <= 7.8.3 Search vendor "Websense" for product "Triton Ap Web" and version " <= 7.8.3" | - |
Affected
| ||||||
Websense Search vendor "Websense" | V-series Appliances Search vendor "Websense" for product "V-series Appliances" | 7.7 Search vendor "Websense" for product "V-series Appliances" and version "7.7" | - |
Affected
|