CVE-2005-3522
ManageEngine Netflow Analyzer 4.0.2 - Cross-Site Scripting via grDisp Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3522. PoCs published by [email protected].
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in NetFlow Analyzer 4 by injecting arbitrary script code via the 'grDisp' parameter in the URL. The PoC includes examples of HTML and JavaScript injection to execute in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in NetFlow Analyzer 4 by injecting arbitrary script code via the 'grDisp' parameter in the URL. The PoC includes examples of HTML and JavaScript injection to execute in the context of the affected site.