First published: Mon Jun 22 2009(Updated: )
Cross-site scripting (XSS) vulnerability in report/ReportViewAction.do in WebNMS Free Edition 5 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebNMS Framework | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-2155 is considered medium due to its potential for XSS exploitation.
To fix CVE-2009-2155, ensure that user input is properly sanitized and encoded in the affected WebNMS Free Edition software.
CVE-2009-2155 affects users of WebNMS Free Edition version 5.
CVE-2009-2155 is a cross-site scripting (XSS) vulnerability.
The exploitation of CVE-2009-2155 allows attackers to inject arbitrary web scripts or HTML into the application.