Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T20:50:17.993Z
Reserved: 2012-09-15T00:00:00
Link: CVE-2012-4923

No data.

Status : Deferred
Published: 2012-09-15T17:55:07.223
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-4923

No data.