CVE-2012-4889

NUCLEI

ManageEngine Firewall Analyzer 7.2 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) tab parameter to createAnomaly.do; (3) url, (4) subTab, or (5) tab parameter to mindex.do; (6) tab parameter to index2.do; or (7) port parameter to syslogViewer.do.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Vulnerability Research Laboratory · textwebappsjava
https://www.exploit-db.com/exploits/37032
exploitdb WORKING POC VERIFIED
by Vulnerability Research Laboratory · textwebappsjava
https://www.exploit-db.com/exploits/37031
exploitdb WORKING POC VERIFIED
by Vulnerability Research Laboratory · textwebappsjava
https://www.exploit-db.com/exploits/37030
exploitdb WORKING POC VERIFIED
by Vulnerability Research Laboratory · textwebappsjava
https://www.exploit-db.com/exploits/37029
exploitdb WORKING POC
webappshardware
https://www.exploit-db.com/exploits/35933

Nuclei Templates (1)

ManageEngine Firewall Analyzer 7.2 - Cross-Site Scripting
MEDIUMby daffainfo

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74538
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48657
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80874
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80875
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52841
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80873
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80872

Scores

EPSS 0.0376
EPSS Percentile 88.1%

Details

CWE
CWE-79
Status published
Products (1)
manageengine/firewall_analyzer 7.2
Published Sep 10, 2012
Tracked Since Feb 18, 2026