CVE-2023-26788

Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address.
Configurations

Configuration 1 (hide)

cpe:2.3:o:veritas:netbackup_appliance_firmware:4.1.0.1:*:*:*:*:*:*:*

History

14 Apr 2023, 03:53

Type Values Removed Values Added
References (MISC) https://github.com/IthacaLabs/Veritas-Technologies - (MISC) https://github.com/IthacaLabs/Veritas-Technologies - Vendor Advisory
References (MISC) https://github.com/IthacaLabs/Veritas-Technologies/blob/main/Veritas%20Appliance%20v4.1.0.1/HHI/HHI_CVE-2023-26788.txt - (MISC) https://github.com/IthacaLabs/Veritas-Technologies/blob/main/Veritas%20Appliance%20v4.1.0.1/HHI/HHI_CVE-2023-26788.txt - Exploit, Vendor Advisory
CPE cpe:2.3:o:veritas:netbackup_appliance_firmware:4.1.0.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Veritas
Veritas netbackup Appliance Firmware
CWE CWE-79

10 Apr 2023, 13:37

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-10 13:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-26788

Mitre link : CVE-2023-26788

CVE.ORG link : CVE-2023-26788


JSON object : View

Products Affected

veritas

  • netbackup_appliance_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')