CVE-2014-5103: XSS
Published Jul 25, 2014
·Updated
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the jusername parameter to event/jsecuritycheck. Fixed in Version 10 Build 10000.
Affected Software
1 affected component
ZohoCorp Manageengine Eventlog Analyzer=9.0-9000
Event History
Jul 25, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5103?
CVE-2014-5103 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2014-5103?
To fix CVE-2014-5103, upgrade to ZOHO ManageEngine EventLog Analyzer version 10 build 10000 or later.
3
What software is affected by CVE-2014-5103?
CVE-2014-5103 affects ZOHO ManageEngine EventLog Analyzer version 9 build 9000.
4
What type of attack does CVE-2014-5103 facilitate?
CVE-2014-5103 facilitates remote attackers to perform cross-site scripting attacks.
5
Can CVE-2014-5103 be exploited through user input?
Yes, CVE-2014-5103 can be exploited through unauthorized input in the j_username parameter.