CVE-2015-4174

Cross-site scripting (XSS) vulnerability in the integrated web server on the Siemens Climatix BACnet/IP communication module with firmware before 10.34 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:o:siemens:climatix_bacnet\/ip:*:*:*:*:*:*:*:*

Information

Published : 2015-06-28 03:59

Updated : 2016-12-07 10:11


NVD link : CVE-2015-4174

Mitre link : CVE-2015-4174


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

siemens

  • climatix_bacnet\/ip