CVE-2015-7997
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
MĂșltiples vulnerabilidades de XSS en la API Nitro en Citrix NetScaler Application Delivery Controller (ADC) y NetScaler Gateway en versiones anteriores a 10.1 Build 133.9, 10.5 en versiones anteriores a Build 58.11 y 10.5.e en versiones anteriores a Build 56.1505.e en dispositivos NetScaler Service Delivery Appliance Service VM (SVM) permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a travĂ©s de vectores no especificados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-10-28 CVE Reserved
- 2015-11-17 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1034167 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://support.citrix.com/article/CTX202482 | 2016-12-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Netscaler Service Delivery Appliance Service Vm Search vendor "Citrix" for product "Netscaler Service Delivery Appliance Service Vm" | 10.5e Search vendor "Citrix" for product "Netscaler Service Delivery Appliance Service Vm" and version "10.5e" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Firmware Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" | 10.1 Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" and version "10.1" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Firmware Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" | 10.5 Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" and version "10.5" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | 10.1 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version "10.1" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | 10.5 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version "10.5" | - |
Affected
|