Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-4891. PoCs published by Ertebat Gostar Co.
AI-analyzed exploit summary The exploit demonstrates directory traversal and XSS vulnerabilities in ManageEngine Firewall Analyzer. It provides URLs to access sensitive files (e.g., web.xml) and execute XSS payloads.
Description
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit demonstrates directory traversal and XSS vulnerabilities in ManageEngine Firewall Analyzer. It provides URLs to access sensitive files (e.g., web.xml) and execute XSS payloads.