CVE-2013-5695

Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/auditlog/, (2) PATH_INFO to info/host/ or (3) viewport/, (4) back parameter to login, or (5) "from" parameter to status/service/recheck.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
opsviewopsview
𝑥
≤ 4.4
opsviewopsview
𝑥
≤ 4.4
opsviewopsview
2.7
opsviewopsview
2.8
opsviewopsview
2.10
opsviewopsview
2.12
opsviewopsview
2.14
opsviewopsview
3.0
opsviewopsview
3.1
opsviewopsview
3.2
opsviewopsview
3.4
opsviewopsview
3.6
opsviewopsview
3.8
opsviewopsview
3.10
opsviewopsview
3.12
opsviewopsview
3.14
opsviewopsview
4.0
opsviewopsview
4.0
opsviewopsview
4.1
opsviewopsview
4.1
opsviewopsview
4.2
opsviewopsview
4.2
opsviewopsview
4.3
opsviewopsview
4.3
𝑥
= Vulnerable software versions