This document details multiple vulnerabilities in OpenNMS, including HTTP Response Splitting and Cross-Site Scripting (XSS). It provides proof-of-concept URLs demonstrating how an attacker can inject malicious headers or execute arbitrary JavaScript in the context of the affected site.
Classification
Writeup 100%
Attack Type
Xss | Other
Complexity
Trivial
Reliability
Reliable
Target:OpenNMS 1.5.93-1
No auth needed
Prerequisites:Network access to the OpenNMS server