PT-2008-5570 · Opennms · Opennms
Publicado
2008-09-29
·
Atualizado
2017-08-08
·
CVE-2008-4320
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenNMS versions prior to 1.5.94
Description:
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the
j username parameter to "j acegi security check", the username parameter to "notification/list.jsp", and the filter parameter to "event/list".Recommendations:
For versions prior to 1.5.94, update to version 1.5.94 or later to resolve the issue. As a temporary workaround, consider restricting access to the "j acegi security check", "notification/list.jsp", and "event/list" endpoints until the update is applied. Avoid using the
j username, username, and filter parameters in the affected endpoints until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opennms