First published: Mon Feb 13 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine ADManager Plus | =5.2-build5210 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1049 is categorized as a medium severity vulnerability due to its potential for denial of service and data manipulation.
To mitigate CVE-2012-1049, upgrade to the latest version of ManageEngine ADManager Plus that addresses these XSS vulnerabilities.
CVE-2012-1049 allows attackers to execute arbitrary web scripts or HTML, potentially leading to session hijacking or phishing attacks.
CVE-2012-1049 affects ManageEngine ADManager Plus version 5.2 Build 5210.
The exploit for CVE-2012-1049 involves the domainName parameter in jsp/AddDC.jsp and the operation parameter in DomainConfig.do.