CVE Database
/

CVE-2007-3594

Back to search

CVE-2007-3594

Published: Jul 6, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName, (3) displayName, and (4) selectedNode parameters to (c) reports/ReportViewAction.do; the (5) operation parameter to (d) admin/ServiceConfiguration.do; and the (6) selectedNode and (7) selectedTab parameters to (e) admin/DeviceAssociation.do. NOTE: the searchTerm parameter in Search.do is already covered by CVE-2006-2343.

VendorProductVersions

n/a

n/a

affected
n/a

References

24767
vdb-entry
x_refsource_BID
38949
vdb-entry
x_refsource_OSVDB
37825
vdb-entry
x_refsource_OSVDB
38947
vdb-entry
x_refsource_OSVDB
37821
vdb-entry
x_refsource_OSVDB
38946
vdb-entry
x_refsource_OSVDB
37824
vdb-entry
x_refsource_OSVDB
37822
vdb-entry
x_refsource_OSVDB
38945
vdb-entry
x_refsource_OSVDB
38948
vdb-entry
x_refsource_OSVDB
37823
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now