Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.securityfocus.com/archive/1/534124 | Exploit Third Party Advisory VDB Entry | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
Configuration 3 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2020-01-31 22:15
Updated : 2020-02-05 18:08
NVD link : CVE-2014-3809
Mitre link : CVE-2014-3809
CVE.ORG link : CVE-2014-3809
JSON object : View
Products Affected
                nokia
- 1830_photonic_service_switch-4
 - 1830_photonic_service_switch-16
 - 1830_photonic_service_switch-32
 - 1830_photonic_service_switch-32_firmware
 - 1830_photonic_service_switch-16_firmware
 - 1830_photonic_service_switch-4_firmware
 
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
