Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2015-2475 | First vendor Publication | 2015-08-14 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Cross-site scripting (XSS) vulnerability in uddi/search/frames.aspx in the UDDI Services component in Microsoft Windows Server 2008 SP2 and BizTalk Server 2010, 2013 Gold, and 2013 R2 allows remote attackers to inject arbitrary web script or HTML via the search parameter, aka "UDDI Services Elevation of Privilege Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2475 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 3 | |
Os | 1 |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2015-08-13 | IAVM : 2015-B-0097 - Microsoft Windows UDDI Cross Site Scripting Vulnerability (MS15-087) Severity : Category II - VMSKEY : V0061287 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2015-08-14 | Name : The remote Windows host is affected by an elevation of privilege vulnerability. File : smb_nt_ms15-087.nasl - Type : ACT_GATHER_INFO |
2015-08-13 | Name : The remote Windows host is affected by an elevation of privilege vulnerability. File : microsoft_biztalk_uddi_xss_ms15-087.nasl - Type : ACT_ATTACK |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 12:46:20 |
|
2021-05-04 12:38:57 |
|
2021-04-22 01:47:43 |
|
2020-05-23 00:44:45 |
|
2018-10-13 05:18:55 |
|
2016-12-24 09:24:10 |
|
2016-11-29 00:25:07 |
|
2016-04-27 02:14:36 |
|
2015-10-18 17:24:09 |
|
2015-08-19 00:24:05 |
|
2015-08-18 21:28:25 |
|
2015-08-18 13:35:03 |
|
2015-08-15 09:30:06 |
|