01642 06 11 11 Arrange Call

Arbitrary Web Script Injection in Riverbed Stingray Traffic Manager Virtual Appliance 9.6

CVE-2014-5348 · MEDIUM

CVE-2014-5348

Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.

Learn more about our Web App Pen Testing.