Unrated severityNVD Advisory· Published Nov 19, 2014· Updated May 6, 2026
CVE-2014-7290
CVE-2014-7290
Description
Multiple cross-site scripting (XSS) vulnerabilities in Atlas Systems Aeon 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) Action or (2) Form parameter to aeon.dll.
Affected products
2cpe:2.3:a:atlas_systems:aeon:3.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:atlas_systems:aeon:3.5:*:*:*:*:*:*:*
- cpe:2.3:a:atlas_systems:aeon:3.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- packetstormsecurity.com/files/129114/Atlas-Systems-Aeon-3.5-3.6-Cross-Site-Scripting.htmlnvd
- seclists.org/fulldisclosure/2014/Nov/32nvd
- tetraph.com/security/xss-vulnerability/cve-2014-7290-atlas-systems-aeon-xss-cross-site-scripting-vulnerability/nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/98705nvd
News mentions
0No linked articles in our index yet.