vendor:
Enterprise Messenger Server
by:
Narendra Shinde
5.5
CVSS
MEDIUM
Multiple Cross Site Scripting vulnerabilities
79
CWE
Product Name: Enterprise Messenger Server
Affected Version From: 2
Affected Version To: 2
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
NetSaro Enterprise Messenger v2.0 Multiple Vulnerabilities
NetSaro Enterprise Messenger Server v2.0 is prone to multiple cross-site scripting vulnerabilities as the user-supplied input received via certain parameters is not properly sanitized. This can be exploited by submitting specially crafted input to the affected software. Successful exploitation could allow the attacker to execute arbitrary script code within the user's browser session in the security context of the affected site.
Mitigation:
Input validation and sanitization should be done to prevent XSS attacks.