CVE-2011-1510: XSS
Published Sep 20, 2011
·Updated
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus (SDP) before 8012 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter.
Affected Software
1 affected component
ManageEngine ServiceDesk Plus<=8.0
Event History
Sep 20, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1510?
CVE-2011-1510 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2011-1510?
To mitigate CVE-2011-1510, upgrade ManageEngine ServiceDesk Plus to version 8012 or later.
3
Which versions of ManageEngine ServiceDesk Plus are affected by CVE-2011-1510?
CVE-2011-1510 affects all versions of ManageEngine ServiceDesk Plus prior to 8012.
4
What type of attack does CVE-2011-1510 enable?
CVE-2011-1510 enables remote attackers to perform cross-site scripting (XSS) attacks.
5
What parameter is exploited in CVE-2011-1510?
The searchText parameter in SolutionSearch.do is exploited in CVE-2011-1510.