Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex.
📦
web_ui
Vendor: tenable
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
0
Remote Access
Total CVEs
6
Total Indexed
Avg. EPSS
2.52%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
6.1
CVSS
Severity: MEDIUM
4.3
CVSS
CVE-2014-7280
Exploit Found
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.
Severity: MEDIUM
5.0
CVSS
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.
Severity: MEDIUM