Vulnerabilities > Tenable > Nessus > 5.2.4

DATE CVE VULNERABILITY TITLE RISK
2017-01-05 CVE-2017-5179 Cross-site Scripting vulnerability in Tenable Nessus
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
tenable CWE-79
3.5
2014-07-23 CVE-2014-4980 Information Exposure vulnerability in Tenable Nessus and web UI
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.
network
low complexity
tenable CWE-200
5.0