CVE-2014-4693

Snort <3.0.13 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the eng parameter to snort_import_aliases.php or (2) unspecified variables to snort_select_alias.php.

Scores

EPSS 0.0006
EPSS Percentile 17.2%

Details

CWE
CWE-79
Status published
Products (4)
netgate/pfsense < 2.1.4
netgate/pfsense
pfsense/snort_package < 3.0.12
n/a/n/a
Published Jul 02, 2014
Tracked Since Feb 18, 2026