Lucene search

K
cveMitreCVE-2010-4841
HistorySep 27, 2011 - 7:55 p.m.

CVE-2010-4841

2011-09-2719:55:03
CWE-79
mitre
web.nvd.nist.gov
26
cve
cross-site scripting
xss
vulnerability
manageengine eventlog analyzer 6.1
security
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

45.9%

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile, (5) load, (6) type, or (7) tab parameter to INDEX.do, the (8) reported parameter to INDEX2.do, the (9) gId parameter to hostlist.do, the (10) newWindow parameter to globalSettings.do, or the (11) STATUS parameter to enableHost.do. Fixed in Build 9000.

Affected configurations

Nvd
Node
manageengineeventlog_analyzerMatch6.1
VendorProductVersionCPE
manageengineeventlog_analyzer6.1cpe:2.3:a:manageengine:eventlog_analyzer:6.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

45.9%

Related for CVE-2010-4841