First published: Thu Mar 28 2013(Updated: )
Cross-site scripting (XSS) vulnerability in EMC Smarts IP Manager, Smarts Service Assurance Manager, Smarts Server Manager, Smarts VoIP Availability Manager, Smarts Network Protocol Manager, and Smarts MPLS Manager before 9.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Smarts IP Manager | =9.1 | |
Emc Smarts Mpls Manager | =9.1 | |
Emc Smarts Network Protocol Manager | =9.1 | |
EMC Smarts Server Manager | =9.1 | |
EMC Smarts Services Assurance Manager | =9.1 | |
Emc Smarts Voip Availability Manager | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0936 is considered a high severity vulnerability due to its potential for remote code execution through cross-site scripting.
To fix CVE-2013-0936, upgrade to version 9.2 or later of affected EMC Smarts products.
CVE-2013-0936 affects EMC Smarts IP Manager, Smarts Service Assurance Manager, Smarts Server Manager, Smarts VoIP Availability Manager, Smarts Network Protocol Manager, and Smarts MPLS Manager all at version 9.1.
CVE-2013-0936 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2013-0936 can be exploited remotely by attackers targeting the affected EMC Smarts products.