Lucene search

K
cvelistMitreCVELIST:CVE-2012-1062
HistoryFeb 14, 2012 - 12:00 a.m.

CVE-2012-1062

2012-02-1400:00:00
mitre
www.cve.org
2

AI Score

5.6

Confidence

High

EPSS

0.004

Percentile

73.0%

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or HTML via the (1) period parameter to showHistoryData.do; (2) selectedNetwork, (3) network, or (4) group parameters to showresource.do; (5) header parameter to AlarmView.do; or (6) attName parameter to jsp/PopUp_Graph.jsp. NOTE: the Search.do/query vector is already covered by CVE-2008-1566, and the jsp/ThresholdActionConfiguration.jsp redirectto vector is already covered by CVE-2008-0474.

AI Score

5.6

Confidence

High

EPSS

0.004

Percentile

73.0%

Related for CVELIST:CVE-2012-1062