Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of malicious scripts.
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.
Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts.
Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use.
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.
Controller may be loaded with malicious firmware which could enable remote code execution
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message.
Server information leak of configuration data when an error is generated in response to a specially crafted message.
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller.
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.