CVE-2011-0767
Imperva SecureSphere Web Application Firewall 6.2, 7.x, 8.x - Cross-Site Scripting via HTTP Request
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall 6.2, 7.x, and 8.x allows remote attackers to inject arbitrary web script or HTML via an HTTP request to a firewalled server, aka Bug ID 31759.
References (5)
Core 5
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/44772
Various Sources x_refsource_misc
http://www.secureworks.com/research/advisories/SWRX-2011-001/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67779
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/567774
Vendor Advisory x_refsource_confirm
http://www.imperva.com/resources/adc/adc_advisories_response_secureworks.html
Scores
EPSS
0.0125
EPSS Percentile
66.2%
Details
CWE
CWE-79
Status
published
Products (7)
imperva/securesphere_web_application_firewall
6.2
imperva/securesphere_web_application_firewall
7.0
imperva/securesphere_web_application_firewall
7.0.0.7061
imperva/securesphere_web_application_firewall
7.0.0.7078
imperva/securesphere_web_application_firewall
7.5
imperva/securesphere_web_application_firewall
8.0
imperva/securesphere_web_application_firewall
8.5
Published
Jun 06, 2011
Tracked Since
Feb 18, 2026