vendor:
Zenoss
by:
SecurityFocus
8,8
CVSS
HIGH
Multiple arbitrary command-execution, HTML-injection, open-redirection, directory-traversal, information-disclosure, code-execution vulnerabilities
78, 79, 601, 22, 200, 94
CWE
Product Name: Zenoss
Affected Version From: Zenoss 3.2.1 and prior
Affected Version To: Zenoss 3.2.1 and prior
Patch Exists: YES
Related CWE: N/A
CPE: a:zenoss:zenoss
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Zenoss Security Vulnerabilities
An attacker can exploit these issues to retrieve arbitrary files, redirect a user to a potentially malicious site, execute arbitrary commands, execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials to perform unauthorized actions in the context of a user's session, or disclose sensitive-information.
Mitigation:
Update to the latest version of Zenoss