CVE-2014-9224

Symantec SCSP/SDCS:SA <6.0 MP1 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-9224.

AI-analyzed exploit summary The provided code includes a functional Python script demonstrating an unauthenticated SQL injection vulnerability in Symantec Data Center Security: Server Advanced (SDCS:SA) via the /sis-ui/authenticate endpoint. It also details multiple other vulnerabilities, including XSS, information disclosure, and policy bypasses.

Description

Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Exploits (1)

exploitdb WORKING POC
webappsmultiple
https://www.exploit-db.com/exploits/35915

The provided code includes a functional Python script demonstrating an unauthenticated SQL injection vulnerability in Symantec Data Center Security: Server Advanced (SDCS:SA) via the /sis-ui/authenticate endpoint. It also details multiple other vulnerabilities, including XSS, information disclosure, and policy bypasses.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Symantec Data Center Security: Server Advanced (SDCS:SA) and Symantec Critical System Protection (SCSP)
No auth needed
Prerequisites: Network access to the target server · Python environment to run the exploit script
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534527/100/0/threaded
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/91
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72093

Scores

EPSS 0.0459
EPSS Percentile 90.4%

Details

CWE
CWE-79
Status published
Products (2)
broadcom/symantec_critical_system_protection 5.2.9
symantec/data_center_security 6.0.0
Published Jan 21, 2015
Tracked Since Feb 18, 2026