Lucene search

K
cveMitreCVE-2011-5105
HistoryAug 23, 2012 - 8:55 p.m.

CVE-2011-5105

2012-08-2320:55:02
CWE-79
mitre
web.nvd.nist.gov
21
cve-2011-5105
xss
zoho manageengine
adselfservice plus
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.871

Percentile

98.7%

Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2) searchString parameters, a different vulnerability than CVE-2010-3274.

Affected configurations

Nvd
Node
zohocorpmanageengine_adselfservice_plusMatch4.5
VendorProductVersionCPE
zohocorpmanageengine_adselfservice_plus4.5cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:4.5:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.871

Percentile

98.7%