Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0474 (Applications Manager)

BugsAlert Home > CVE-2008-0474 (Applications Manager)
 
 

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) sh...




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0474

Learn more about CVE-2008-0474 (Applications Manager)
 
Tags: cve-2008-0474 applications manager

Related Items

      News: Radio Free Europe hit by DDoS attack

      Vuln: Microsoft XML Core Services Race Condition Memory Corruption Vulnerability

      CVE-2008-2236 (blosxom)

      CVE-2007-6410 (Gadu-Gadu Instant Messenger)

      FrSIRT - Sun Solaris vuidmice STREAMS Modules Denial of Service Vulnerability

      FrSIRT - IBM AIX Privilege Escalation and Remote Code Execution Vulnerabilities

      Mandriva: Updated xine-lib packages fix vulnerability in

 

Pixel