Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-4939. PoCs published by Anthony Trummer.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in SolarWinds Orion IP Address Manager (IPAM) 3.0 by injecting a malicious script via the 'q' parameter in the search.aspx page. The PoC uses a simple alert payload to confirm the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in SolarWinds Orion IP Address Manager (IPAM) 3.0 by injecting a malicious script via the 'q' parameter in the search.aspx page. The PoC uses a simple alert payload to confirm the vulnerability.