PT-2012-3040 · Zoho · Zoho Manageengine Admanager Plus

Gjoko Krstic

·

Published

2012-02-13

·

Updated

2017-08-29

·

CVE-2012-1049

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine ADManager Plus version 5.2 Build 5210
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the vulnerabilities can be exploited via the domainName parameter to "jsp/AddDC.jsp" or the operation parameter to "DomainConfig.do".
Recommendations For ManageEngine ADManager Plus version 5.2 Build 5210, consider restricting access to the "jsp/AddDC.jsp" and "DomainConfig.do" endpoints until a patch is available. As a temporary workaround, avoid using the domainName and operation parameters in the affected API endpoints.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1049

Affected Products

Zoho Manageengine Admanager Plus