CVE-2012-2577 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation (2) syscontact or (3) sysName field of an snmpd.conf file.

Reference

http://secunia.com/advisories/50004 http://www.kb.cert.org/vuls/id/174119 http://www.securityfocus.com/bid/54624 http://www.solarwinds.com/documentation/Orion/docs/ReleaseNotes/releaseNotes.htm https://exchange.xforce.ibmcloud.com/vulnerabilities/77147

Share on: