CVE-2012-0936 Information

Description

Cross-site scripting (XSS) vulnerability in web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java in OpenNMS 1.8.x before 1.8.17 1.9.93 and earlier and 1.10.x before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via the Username field related to login.

Reference

http://fisheye.opennms.org/browse/opennms/features/springframework-security/src/main/java/org/opennms/web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java?r2=d2ce15470cb6c87c115c918eb86ef147486a9166&r1=80b80e110e4bce568fc2c6c0a15a http://issues.opennms.org/browse/NMS/fixforversion/10824atl_token=BCL8-RCDX-MB62-2EZT7C38eaf469042162355c28f5393587690a8388d5567Clout&selectedTab=com.atlassian.jira.plugin.system.project3Aversion-summary-panel http://issues.opennms.org/browse/NMS/fixforversion/10825 http://issues.opennms.org/browse/NMS-5128?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanelissue-tabs http://osvdb.org/78454 http://secunia.com/advisories/47646 http://www.securityfocus.com/bid/51632 https://exchange.xforce.ibmcloud.com/vulnerabilities/72625

Share on: