CVE-2012-0936 Information
Description
Cross-site scripting (XSS) vulnerability in web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java in OpenNMS 1.8.x before 1.8.17 1.9.93 and earlier and 1.10.x before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via the Username field related to login.
Reference
http://fisheye.opennms.org/browse/opennms/features/springframework-security/src/main/java/org/opennms/web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java?r2=d2ce15470cb6c87c115c918eb86ef147486a9166&r1=80b80e110e4bce568fc2c6c0a15a http://issues.opennms.org/browse/NMS/fixforversion/10824atl_token=BCL8-RCDX-MB62-2EZT7C38eaf469042162355c28f5393587690a8388d5567Clout&selectedTab=com.atlassian.jira.plugin.system.project3Aversion-summary-panel http://issues.opennms.org/browse/NMS/fixforversion/10825 http://issues.opennms.org/browse/NMS-5128?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanelissue-tabs http://osvdb.org/78454 http://secunia.com/advisories/47646 http://www.securityfocus.com/bid/51632 https://exchange.xforce.ibmcloud.com/vulnerabilities/72625
Share on: