CVE-2012-4344: XSS
Published Aug 15, 2012
·Updated
Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the SNMP system name of the attacking host.
Affected Software
2 affected components
Progress WhatsUp Gold=15.02
Ipswitch WhatsUp Gold=15.02
Event History
Aug 15, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4344?
CVE-2012-4344 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2012-4344?
To fix CVE-2012-4344, upgrade to a patched version of Ipswitch WhatsUp Gold that addresses this XSS vulnerability.
3
Who is affected by CVE-2012-4344?
CVE-2012-4344 affects users of Ipswitch WhatsUp Gold version 15.02.
4
What type of vulnerability is CVE-2012-4344?
CVE-2012-4344 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.
5
What can attackers do with CVE-2012-4344?
Attackers exploiting CVE-2012-4344 can inject arbitrary web scripts or HTML into the affected application.