.. / CVE-2012-4889

Exploit for ManageEngine Firewall Analyzer 7.2 - Cross-Site Scripting (CVE-2012-4889)

Description:

Multiple cross-site scripting vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) tab parameter to createAnomaly.do; (3) url, (4) subTab, or (5) tab parameter to mindex.do; (6) tab parameter to index2.do; or (7) port parameter to syslogViewer.do.

Nuclei Template

View the template here CVE-2012-4889.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2012/CVE-2012-4889.yaml
Copy

References:

https://exchange.xforce.ibmcloud.com/vulnerabilities/74538
https://nvd.nist.gov/vuln/detail/CVE-2012-4889
https://github.com/ARPSyndicate/kenzer-templates
http://packetstormsecurity.org/files/111474/VL-437.txt
http://www.vulnerability-lab.com/get_content.php?id=437