CVE-2011-0552

Symantec IM Manager < 8.4.17 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec IM Manager before 8.4.18 allow remote attackers to inject arbitrary web script or HTML via the (1) refreshRateSetting parameter to IMManager/Admin/IMAdminSystemDashboard.asp, the (2) nav or (3) menuitem parameter to IMManager/Admin/IMAdminTOC_simple.asp, or the (4) action parameter to IMManager/Admin/IMAdminEdituser.asp.

Scores

EPSS 0.0053
EPSS Percentile 66.7%

Classification

CWE
CWE-79
Status published

Affected Products (21)

symantec/im_manager < 8.4.17
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
symantec/im_manager
... and 6 more

Timeline

Published Oct 02, 2011
Tracked Since Feb 18, 2026