MEDIUM🇬🇧 English

CVE-2016-9834

CVSS 6.1v3.0pub. 2017-06-07upd. 2026-05-13

An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a request to the "LiveConnectionDetail.jsp" application. GET parameters "applicationname" and "username" are improperly sanitized allowing an attacker to inject arbitrary JavaScript into the page. This can be abused by an attacker to perform a cross-site scripting attack on the user. A vulnerable URI is /corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.

oryginał EN
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Sophos Cyberoam

    HW
    Sophos
    wszystkie wersje
  • Sophos Cyberoam Firmware

    OS
    Sophos
    ≤ 10.6.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSSFirewall
CWE
Referencje

Powiązane podatności

CVE-2019-17059CRITICAL9.8PL ✓ten sam produkt

Sophos Cyberoam – command injection w panelu Web Admin i SSL VPN

CVE-2023-1671CRITICAL9.8⚠ KEVPL ✓ten sam vendor

Pre-auth command injection w Sophos Web Appliance (RCE)

CVE-2022-3236CRITICAL9.8⚠ KEVPL ✓ten sam vendor

Code injection w Sophos Firewall — RCE przez User Portal i Webadmin

CVE-2022-1040CRITICAL9.8⚠ KEVPL ✓ten sam vendor

Authentication Bypass z możliwością RCE w Sophos Firewall

CVE-2020-29574CRITICAL9.8⚠ KEVPL ✓ten sam vendor

SQL Injection w Sophos Cyberoam OS — zdalny dostęp bez uwierzytelnienia