OpenNMS Unspecified Multiple Cross Site Scripting Vulnerabilities
BID:67774
Info
OpenNMS Unspecified Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 67774 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3960 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2014 12:00AM |
| Updated: | Jun 25 2014 04:35PM |
| Credit: | Vendor reported this issue. |
| Vulnerable: |
OpenNMS OpenNMS 1.5.96 OpenNMS OpenNMS 1.5.95 OpenNMS OpenNMS 1.5.94 OpenNMS OpenNMS 1.5.93 OpenNMS OpenNMS 1.5.92 OpenNMS OpenNMS 1.5.91 OpenNMS OpenNMS 1.5.90 OpenNMS OpenNMS 1.9.93 OpenNMS OpenNMS 1.8.17 OpenNMS OpenNMS 1.8.16 OpenNMS OpenNMS 1.10.0 |
| Not Vulnerable: | |
Discussion
OpenNMS Unspecified Multiple Cross Site Scripting Vulnerabilities
OpenNMS is prone to multiple cross-site-scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to OpenNMS 1.12.7 are vulnerable.
OpenNMS is prone to multiple cross-site-scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to OpenNMS 1.12.7 are vulnerable.
Exploit / POC
OpenNMS Unspecified Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
OpenNMS Unspecified Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenNMS Unspecified Multiple Cross Site Scripting Vulnerabilities
References:
References: