CVE-2010-4841: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOSTID, (2) OS, (3) GROUP, (4) exportFile, (5) load, (6) type, or (7) tab parameter to INDEX.do, the (8) reported parameter to INDEX2.do, the (9) gId parameter to hostlist.do, the (10) newWindow parameter to globalSettings.do, or the (11) STATUS parameter to enableHost.do. Fixed in Build 9000.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4841?
CVE-2010-4841 is considered a high severity vulnerability due to its potential for remote code execution via cross-site scripting.
How do I fix CVE-2010-4841?
To fix CVE-2010-4841, update ManageEngine EventLog Analyzer to the latest version that addresses these cross-site scripting vulnerabilities.
What software is affected by CVE-2010-4841?
CVE-2010-4841 affects ManageEngine EventLog Analyzer version 6.1.
What type of vulnerability is CVE-2010-4841?
CVE-2010-4841 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Can CVE-2010-4841 be exploited remotely?
Yes, CVE-2010-4841 can be exploited remotely by attackers without authentication.