CVE-2012-2577
SolarWinds Orion NPM <10.3.1 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.
Exploits (1)
References (5)
Scores
EPSS
0.2183
EPSS Percentile
95.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (9)
solarwinds/orion_network_performance_monitor
< 10.2
solarwinds/orion_network_performance_monitor
solarwinds/orion_network_performance_monitor
solarwinds/orion_network_performance_monitor
solarwinds/orion_network_performance_monitor
solarwinds/orion_network_performance_monitor
solarwinds/orion_network_performance_monitor
solarwinds/orion_network_performance_monitor
solarwinds/orion_network_performance_monitor
Timeline
Published
Aug 12, 2012
Tracked Since
Feb 18, 2026