PT-2015-7108 · Ipswitch · Ipswitch Whatsup Gold
Deral Heiland
·
Published
2015-12-27
·
Updated
2024-08-27
·
CVE-2015-6005
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IPSwitch WhatsUp Gold versions prior to 16.4
Description
The issue allows remote attackers to inject arbitrary web script or HTML via multiple fields, including (1) an SNMP OID object, (2) an SNMP trap message, (3) the
View Names field, (4) the Group Names field, (5) the Flow Monitor Credentials field, (6) the Flow Monitor Threshold Name field, (7) the Task Library Name field, (8) the Task Library Description field, (9) the Policy Library Name field, (10) the Policy Library Description field, (11) the Template Library Name field, (12) the Template Library Description field, (13) the System Script Library Name field, (14) the System Script Library Description field, or (15) the CLI Settings Library Description field.Recommendations
For IPSwitch WhatsUp Gold versions prior to 16.4, update to version 16.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the mentioned fields to minimize the risk of exploitation. Avoid using the mentioned fields in the affected versions until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipswitch Whatsup Gold