CVE-2014-3809

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
31/01/2020
Last modified:
05/02/2020

Description

Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nokia:1830_photonic_service_switch-4_firmware:*:*:*:*:*:*:*:* 6.0 (including)
cpe:2.3:h:nokia:1830_photonic_service_switch-4:-:*:*:*:*:*:*:*
cpe:2.3:o:nokia:1830_photonic_service_switch-16_firmware:*:*:*:*:*:*:*:* 6.0 (including)
cpe:2.3:h:nokia:1830_photonic_service_switch-16:-:*:*:*:*:*:*:*
cpe:2.3:o:nokia:1830_photonic_service_switch-32_firmware:*:*:*:*:*:*:*:* 6.0 (including)
cpe:2.3:h:nokia:1830_photonic_service_switch-32:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools