Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-15851 | An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript code execution, resulting in the execution of javascript code running on the victim's browser. An attacker can get a victim to click a link, or embedded URL, that redirects to the reflected cross-site scripting vulnerability to trigger this vulnerability. |
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-05T05:04:28.881Z
Reserved: 2018-01-02T00:00:00.000Z
Link: CVE-2018-4065
No data.
Status : Modified
Published: 2019-05-06T19:29:00.700
Modified: 2026-06-17T01:58:18.917
Link: CVE-2018-4065
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD