VulnerabilityModified
CVE-2012-4344
Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the SNMP system name of the attacking host.
MEDIUM 4.3EPSS 3.81%
Does this matter?
Lower severity and a low EPSS score (3.81%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the SNMP system name of the attacking host.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 3.81% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- progress/whatsup gold
- Source
- cve@mitre.org
References
- http://www.exploit-db.com/exploits/20035Exploit
- http://www.kb.cert.org/vuls/id/777007US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77150
- http://www.exploit-db.com/exploits/20035Exploit
- http://www.kb.cert.org/vuls/id/777007US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77150
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.