Lucene search

K
cveMitreCVE-2012-1062
HistoryFeb 14, 2012 - 12:55 a.m.

CVE-2012-1062

2012-02-1400:55:01
CWE-79
mitre
web.nvd.nist.gov
45
cve-2012-1062
cross-site scripting
manageengine applications manager
xss
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.6

Confidence

High

EPSS

0.004

Percentile

73.0%

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or HTML via the (1) period parameter to showHistoryData.do; (2) selectedNetwork, (3) network, or (4) group parameters to showresource.do; (5) header parameter to AlarmView.do; or (6) attName parameter to jsp/PopUp_Graph.jsp. NOTE: the Search.do/query vector is already covered by CVE-2008-1566, and the jsp/ThresholdActionConfiguration.jsp redirectto vector is already covered by CVE-2008-0474.

Affected configurations

Nvd
Node
manageengineapplications_managerMatch10.0
OR
manageengineapplications_managerMatch10.1
OR
manageengineapplications_managerMatch10.2
OR
manageengineapplications_managerMatch10.3
Node
manageengineapplications_managerMatch9
OR
manageengineapplications_managerMatch9.1
OR
manageengineapplications_managerMatch9.2
OR
manageengineapplications_managerMatch9.3
OR
manageengineapplications_managerMatch9.4
OR
manageengineapplications_managerMatch9.5
VendorProductVersionCPE
manageengineapplications_manager10.0cpe:2.3:a:manageengine:applications_manager:10.0:*:*:*:*:*:*:*
manageengineapplications_manager10.1cpe:2.3:a:manageengine:applications_manager:10.1:*:*:*:*:*:*:*
manageengineapplications_manager10.2cpe:2.3:a:manageengine:applications_manager:10.2:*:*:*:*:*:*:*
manageengineapplications_manager10.3cpe:2.3:a:manageengine:applications_manager:10.3:*:*:*:*:*:*:*
manageengineapplications_manager9cpe:2.3:a:manageengine:applications_manager:9:*:*:*:*:*:*:*
manageengineapplications_manager9.1cpe:2.3:a:manageengine:applications_manager:9.1:*:*:*:*:*:*:*
manageengineapplications_manager9.2cpe:2.3:a:manageengine:applications_manager:9.2:*:*:*:*:*:*:*
manageengineapplications_manager9.3cpe:2.3:a:manageengine:applications_manager:9.3:*:*:*:*:*:*:*
manageengineapplications_manager9.4cpe:2.3:a:manageengine:applications_manager:9.4:*:*:*:*:*:*:*
manageengineapplications_manager9.5cpe:2.3:a:manageengine:applications_manager:9.5:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.6

Confidence

High

EPSS

0.004

Percentile

73.0%