CVE

Id
95969  
CVE No.
CVE-2016-9149  
Status
Candidate  
Description
The Addresses Object parser in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 mishandles single quote characters, which allows remote authenticated users to conduct XPath injection attacks via a crafted string.  
Phase
Assigned (20161103)  
Votes
None (candidate not yet proposed)  
Comments