CVE-2012-2577
SolarWinds Orion NPM <10.3.1 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.
Exploits (1)
References (5)
Scores
EPSS
0.1875
EPSS Percentile
95.3%
Details
CWE
CWE-79
Status
published
Products (9)
solarwinds/orion_network_performance_monitor
7.8.5
solarwinds/orion_network_performance_monitor
8.5
solarwinds/orion_network_performance_monitor
8.5.1
solarwinds/orion_network_performance_monitor
9.0
solarwinds/orion_network_performance_monitor
9.1
solarwinds/orion_network_performance_monitor
9.5.1
solarwinds/orion_network_performance_monitor
10.0
solarwinds/orion_network_performance_monitor
10.1
solarwinds/orion_network_performance_monitor
< 10.2
Published
Aug 12, 2012
Tracked Since
Feb 18, 2026