PT-2013-1741 · Trimble · Trimble Infrastructure Gnss Series Receivers Netr3+4

CVE-2012-5053

·

Publicado

2013-03-07

·

Atualizado

2023-12-01

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Trimble Infrastructure GNSS Series Receivers NetR3, NetR5, NetR8, and NetR9 versions prior to 4.70 Trimble Infrastructure GNSS Series Receivers NetRS versions prior to 1.3-2
Description A cross-site scripting (XSS) issue in the Receiver Web User Interface allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. This could potentially lead to unauthorized access or control of the affected systems.
Recommendations For Trimble Infrastructure GNSS Series Receivers NetR3, NetR5, NetR8, and NetR9 versions prior to 4.70, update to version 4.70 or later. For Trimble Infrastructure GNSS Series Receivers NetRS versions prior to 1.3-2, update to version 1.3-2 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-5053

Produtos afetados

Trimble Infrastructure Gnss Series Receivers Netr3
Trimble Infrastructure Gnss Series Receivers Netr5
Trimble Infrastructure Gnss Series Receivers Netr8
Trimble Infrastructure Gnss Series Receivers Netr9
Trimble Infrastructure Gnss Series Receivers Netrs