Lucene search

K
cveCertccCVE-2012-2585
HistoryAug 12, 2012 - 9:55 p.m.

CVE-2012-2585

2012-08-1221:55:01
CWE-79
certcc
web.nvd.nist.gov
53
cve-2012-2585
manageengine
servicedesk plus
xss
vulnerabilities
web security
email security
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

53.7%

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an arbitrary element, or (4) a crafted SRC attribute of an IFRAME element, or an e-mail message subject with (5) a SCRIPT element, (6) a CSS expression property in the STYLE attribute of an arbitrary element, (7) a crafted SRC attribute of an IFRAME element, (8) a crafted CONTENT attribute of an HTTP-EQUIV=“refresh” META element, or (9) a data: URL in the CONTENT attribute of an HTTP-EQUIV=“refresh” META element.

Affected configurations

Nvd
Node
manageengineservicedesk_plusMatch8.1
VendorProductVersionCPE
manageengineservicedesk_plus8.1cpe:2.3:a:manageengine:servicedesk_plus:8.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

53.7%

Related for CVE-2012-2585