CVE-2012-1049: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1049?
CVE-2012-1049 is categorized as a medium severity vulnerability due to its potential for denial of service and data manipulation.
How do I fix CVE-2012-1049?
To mitigate CVE-2012-1049, upgrade to the latest version of ManageEngine ADManager Plus that addresses these XSS vulnerabilities.
What types of attacks are possible with CVE-2012-1049?
CVE-2012-1049 allows attackers to execute arbitrary web scripts or HTML, potentially leading to session hijacking or phishing attacks.
Which versions of ManageEngine ADManager Plus are affected by CVE-2012-1049?
CVE-2012-1049 affects ManageEngine ADManager Plus version 5.2 Build 5210.
What specific parameters are involved in CVE-2012-1049 exploit?
The exploit for CVE-2012-1049 involves the domainName parameter in jsp/AddDC.jsp and the operation parameter in DomainConfig.do.