CVE-2016-9490: ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerability in parameter LIMIT, in URL path /DiagAlertAction.do?REQTYPE=AJAX&LIMIT=1233. The URL is also available without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2016-9490.
What is the severity of CVE-2016-9490?
CVE-2016-9490 has a severity level of medium.
Which software versions are affected by CVE-2016-9490?
ManageEngine Applications Manager versions 12 and 13 before build 13200 are affected by CVE-2016-9490.
How does CVE-2016-9490 affect ManageEngine Applications Manager?
CVE-2016-9490 is a Reflected Cross-Site Scripting vulnerability in ManageEngine Applications Manager versions 12 and 13 before build 13200.
Are there any references for CVE-2016-9490?
Yes, you can find references for CVE-2016-9490 at the following links: [1](http://seclists.org/fulldisclosure/2017/Apr/9), [2](http://www.securityfocus.com/bid/97394), [3](https://packetstormsecurity.com/files/142022/ManageEngine-Applications-Manager-12-13-XSS-SQL-Injection-Code-Execution.html).