Vulnerabilities > CVE-2007-3594 - Cross-Site Scripting vulnerability in Adventnet Manageengine Netflow Analyzer 6/7

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
adventnet
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName, (3) displayName, and (4) selectedNode parameters to (c) reports/ReportViewAction.do; the (5) operation parameter to (d) admin/ServiceConfiguration.do; and the (6) selectedNode and (7) selectedTab parameters to (e) admin/DeviceAssociation.do. NOTE: the searchTerm parameter in Search.do is already covered by CVE-2006-2343.

Vulnerable Configurations

Part Description Count
Application
Adventnet
2

Exploit-Db

  • descriptionOpManager 6/7 ping.do name Parameter XSS. CVE-2007-3594 . Webapps exploit for java platform
    idEDB-ID:30271
    last seen2016-02-03
    modified2007-07-04
    published2007-07-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/30271/
    titleOpManager 6/7 ping.do name Parameter XSS
  • descriptionOpManager 6/7 reports/ReportViewAction.do Multiple Parameter XSS. CVE-2007-3594. Webapps exploit for java platform
    idEDB-ID:30273
    last seen2016-02-03
    modified2007-07-04
    published2007-07-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/30273/
    titleOpManager 6/7 reports/ReportViewAction.do Multiple Parameter XSS
  • descriptionOpManager 6/7 admin/DeviceAssociation.do Multiple Parameter XSS. CVE-2007-3594. Webapps exploit for java platform
    idEDB-ID:30275
    last seen2016-02-03
    modified2007-07-04
    published2007-07-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/30275/
    titleOpManager 6/7 admin/DeviceAssociation.do Multiple Parameter XSS
  • descriptionOpManager 6/7 traceRoute.do name Parameter XSS. CVE-2007-3594. Webapps exploit for java platform
    idEDB-ID:30272
    last seen2016-02-03
    modified2007-07-04
    published2007-07-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/30272/
    titleOpManager 6/7 - traceRoute.do name Parameter XSS
  • descriptionOpManager 6/7 admin/ServiceConfiguration.do operation Parameter XSS a. CVE-2007-3594. Webapps exploit for java platform
    idEDB-ID:30274
    last seen2016-02-03
    modified2007-07-04
    published2007-07-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/30274/
    titleOpManager 6/7 admin/ServiceConfiguration.do operation Parameter XSS