vendor:
ENPS-2012 Print Server
by:
GotGeek Labs
8.8
CVSS
HIGH
Stored Cross-site Scripting
79
CWE
Product Name: ENPS-2012 Print Server
Affected Version From: 6.03.39E 0008 (ZOT-PS-39/6.3.0008)
Affected Version To: Other versions may also be vulnerable.
Patch Exists: YES
Related CWE: N/A
CPE: h:encore:enps-2012
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2011
Encore ENPS-2012 Cross-site Scripting Vulnerability
Web interface from ENPS-2012 Print Server is affected by stored cross-site scripting vulnerability because it fails to properly sanitize user-supplied input at 'NDSContext' field in 'NetWare NDS Settings' area. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
Mitigation:
Input validation should be used to prevent the exploitation of this vulnerability.