MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflow/jspui/appConfig.jsp, the (3) view parameter in (c) netflow/jspui/index.jsp, and the (4) rtype parameter in (d) netflow/jspui/selectDevice.jsp and (e) netflow/jspui/customReport.jsp
Published Jul 6, 2007
4.3
MEDIUMCVSS 2.0
EPSS 4.10%
Description
Affected products
Remediation
Metrics
References (9)
Change history (0)
No recorded changes yet.