CVE-2013-5695

EUVD-2013-5532
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/auditlog/, (2) PATH_INFO to info/host/ or (3) viewport/, (4) back parameter to login, or (5) "from" parameter to status/service/recheck.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
Affected Products (NVD)
VendorProductVersion
opsviewopsview
𝑥
≤ 4.4
opsviewopsview
𝑥
≤ 4.4
opsviewopsview
2.7
opsviewopsview
2.8
opsviewopsview
2.10
opsviewopsview
2.12
opsviewopsview
2.14
opsviewopsview
3.0
opsviewopsview
3.1
opsviewopsview
3.2
opsviewopsview
3.4
opsviewopsview
3.6
opsviewopsview
3.8
opsviewopsview
3.10
opsviewopsview
3.12
opsviewopsview
3.14
opsviewopsview
4.0
opsviewopsview
4.0
opsviewopsview
4.1
opsviewopsview
4.1
opsviewopsview
4.2
opsviewopsview
4.2
opsviewopsview
4.3
opsviewopsview
4.3
𝑥
= Vulnerable software versions