Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.Referenceshttp://seclists.org/fulldisclosure/2015/Dec/117http://packetstormsecurity.com/files/135068/Nordex-Control-2-NC2-SCADA-16-Cross-Site-Scripting.htmlhttps://ics-cert.us-cert.gov/advisories/ICSA-15-286-01