ABB GATE-E2 ICSA-18-352-01 Authentication Bypass and Cross-site Scripting Vulnerability
BID:106247
CVE-2018-18995 | CVE-2018-18997 |Info
ABB GATE-E2 ICSA-18-352-01 Authentication Bypass and Cross-site Scripting Vulnerability
| Bugtraq ID: | 106247 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-18995 CVE-2018-18997 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2018 12:00AM |
| Updated: | Dec 18 2018 12:00AM |
| Credit: | Nelson Berg of Applied Risk |
| Vulnerable: |
ABB GATE-E2 0 ABB GATE-E1 0 |
| Not Vulnerable: | |
Discussion
ABB GATE-E2 ICSA-18-352-01 Authentication Bypass and Cross-site Scripting Vulnerability
ABB GATE-E2 is prone to a cross-site scripting vulnerability and an authentication-bypass vulnerability.
Attackers can exploit these issues to execute arbitrary code in the context of the browser, obtain sensitive information; other attacks may also be possible.
ABB GATE-E2 is prone to a cross-site scripting vulnerability and an authentication-bypass vulnerability.
Attackers can exploit these issues to execute arbitrary code in the context of the browser, obtain sensitive information; other attacks may also be possible.
References
ABB GATE-E2 ICSA-18-352-01 Authentication Bypass and Cross-site Scripting Vulnerability
References:
References: