Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2016-2046
Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.003
EPSS Ranking
54.9%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
http://packetstormsecurity.com/files/135709/Sophos-UTM-9-Cross-Site-Scripting.html
http://seclists.org/fulldisclosure/2016/Feb/60
http://www.halock.com/blog/cve-2016-2046-cross-site-scripting-sophos-utm-9/
http://www.securitytracker.com/id/1035048
http://packetstormsecurity.com/files/135709/Sophos-UTM-9-Cross-Site-Scripting.html
http://seclists.org/fulldisclosure/2016/Feb/60
http://www.halock.com/blog/cve-2016-2046-cross-site-scripting-sophos-utm-9/
http://www.securitytracker.com/id/1035048
Products affected by CVE-2016-2046
Sophos
»
Unified Threat Management Software
»
Version:
8.3
cpe:2.3:a:sophos:unified_threat_management_software:8.3
Sophos
»
Unified Threat Management Software
»
Version:
9.007
cpe:2.3:a:sophos:unified_threat_management_software:9.007
Sophos
»
Unified Threat Management Software
»
Version:
9.107
cpe:2.3:a:sophos:unified_threat_management_software:9.107
Sophos
»
Unified Threat Management Software
»
Version:
9.108
cpe:2.3:a:sophos:unified_threat_management_software:9.108
Sophos
»
Unified Threat Management Software
»
Version:
9.109
cpe:2.3:a:sophos:unified_threat_management_software:9.109
Sophos
»
Unified Threat Management Software
»
Version:
9.318
cpe:2.3:a:sophos:unified_threat_management_software:9.318
Sophos
»
Unified Threat Management Software
»
Version:
9.319
cpe:2.3:a:sophos:unified_threat_management_software:9.319
Sophos
»
Unified Threat Management Software
»
Version:
9.351
cpe:2.3:a:sophos:unified_threat_management_software:9.351
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved