Record summary

CVE-2014-3080 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the key parameter to avctalert.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBIBM GCM16/32 1.20.0.22575 - Multiple VulnerabilitiesExploitDB exploitby Alejandro Alvarez BravoNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

References

7