First published: Mon Jul 29 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or the (3) HelpPage parameter to commonhelp.aspx.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BMC Service Desk Express | =10.2.1.95 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4946 is considered a medium severity vulnerability due to multiple cross-site scripting (XSS) weaknesses.
To fix CVE-2013-4946, you should apply the latest security patches provided by BMC for Service Desk Express version 10.2.1.95.
The exploit targets in CVE-2013-4946 include the SelTab parameter in QV_admin.aspx, the CallBack parameter in QV_grid.aspx, and the HelpPage parameter in commonhelp.aspx.
CVE-2013-4946 affects all installations of BMC Service Desk Express version 10.2.1.95.
CVE-2013-4946 is classified as a cross-site scripting (XSS) vulnerability.