CVE-2012-6658 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation (2) syscontact or (3) sysName configuration in snmpd.conf. NOTE: this entry was SPLIT from CVE-2012-2956 per ADT2 due to different vulnerability types.

Reference

http://osvdb.org/84112 http://secunia.com/advisories/49978/ http://www.exploit-db.com/exploits/20063

Share on: