CVE-2009-4387
22.12.2009, 23:30
The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified inputs.
Vendor | Product | Version |
---|---|---|
manageengine | password_manager_pro | 𝑥 ≤ 6.1 |
manageengine | password_manager_pro | 𝑥 ≤ 6.1 |
manageengine | password_manager_pro | 4.6 |
manageengine | password_manager_pro | 4.7 |
manageengine | password_manager_pro | 4.8 |
manageengine | password_manager_pro | 5.0 |
manageengine | password_manager_pro | 5.1 |
manageengine | password_manager_pro | 5.2 |
manageengine | password_manager_pro | 5.3 |
manageengine | password_manager_pro | 5.4 |
manageengine | password_manager_pro | 6.0 |
𝑥
= Vulnerable software versions