CVE-2015-2960: XSS
Published Jun 9, 2015
·Updated
Cross-site scripting (XSS) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
ZohoCorp Manageengine Netflow Analyzer
Remediation
Event History
Jun 9, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2960?
CVE-2015-2960 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2015-2960?
To fix CVE-2015-2960, upgrade to a version of Zoho NetFlow Analyzer that is beyond build 10250.
3
What are the potential impacts of CVE-2015-2960?
Exploiting CVE-2015-2960 allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data.
4
Which software is affected by CVE-2015-2960?
CVE-2015-2960 affects Zoho ManageEngine NetFlow Analyzer build 10250 and earlier.
5
How can I detect CVE-2015-2960 on my system?
Detecting CVE-2015-2960 involves reviewing web application logs for unusual script injections and ensuring that you are not running affected versions of the software.