Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web script or HTML via the referrer parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IronPort AsyncOS垃圾邮件隔离功能登录页面跨站脚本漏洞
Vulnerability Description
IronPort系列产品是广泛使用的邮件加密网关,AsyncOS是该产品所使用的操作系统,专门用于处理并发通讯的瓶颈以及基于文件的邮件队列的限制。 AsyncOS的垃圾邮件隔离功能的登录页面没有正确地过滤用户所提交的请求,如果远程攻击者提交了带有referrer参数的特制登录请求的话,就可以执行跨站脚本攻击,导致在用户浏览器会话中注入并执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A