Ecava IntegraXor < 3.60.4080 XSS

medium Nessus Plugin ID 55025

Synopsis

The remote Windows host contains a SCADA application that is affected by several cross-site scripting vulnerabilities.

Description

The version of IntegraXor installed on the remote host is earlier than 3.60 (Build 4080). As such, it reportedly is affected by several reflective (non-persistent) cross-site scripting vulnerabilities.

An attacker may be able to leverage this to inject arbitrary HTML and script code into a user's browser to be executed within the security context of the affected site.

Solution

Upgrade to version 3.60.4080.0 or later.

See Also

https://www.integraxor.com/security-issue-xss-vulnerability-note/

Plugin Details

Severity: Medium

ID: 55025

File Name: scada_integraxor_3_60_4080.nbin

Version: 1.69

Type: local

Family: SCADA

Published: 6/9/2011

Updated: 5/20/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

Required KB Items: SCADA/Apps/Ecava/IntegraXor/Installed

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/9/2011

Vulnerability Publication Date: 5/9/2010

Reference Information

CVE: CVE-2011-2958

BID: 48958

ICS-ALERT: 11-147-02