Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.103462
Category:Web application abuses
Title:Multiple Vendor Products Security Vulnerabilities
Summary:Quantum Scalar i500, Dell ML6000, and IBM TS3310 are prone to following vulnerabilities:;; 1. An information disclosure vulnerability;; 2. A cross-site scripting vulnerability;; 3. A cross-site request-forgery vulnerability;; 4. A security bypass vulnerability
Description:Summary:
Quantum Scalar i500, Dell ML6000, and IBM TS3310 are prone to following vulnerabilities:

1. An information disclosure vulnerability

2. A cross-site scripting vulnerability

3. A cross-site request-forgery vulnerability

4. A security bypass vulnerability

Vulnerability Impact:
An attacker may leverage these issues to execute arbitrary script
code in the browser of an unsuspecting user in the context of the
affected site. This may let the attacker steal cookie-based
authentication credentials and launch other attacks. The information-
disclosure vulnerability can allow the attacker to obtain sensitive
information that may aid in launching further attacks.

Exploiting the cross-site request-forgery may allow a remote attacker
to perform certain administrative actions and gain unauthorized access
to the affected application. Other attacks are also possible.

Attackers can exploit a password weakness issue to bypass security
restrictions to obtain sensitive information or perform unauthorized
actions, this may aid in launching further attacks.

Solution:
Updates are available. Check the references.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1841
CERT/CC vulnerability note: VU#913483
http://www.kb.cert.org/vuls/id/913483
http://www.kb.cert.org/vuls/id/MAPG-8NNKN8
http://www.kb.cert.org/vuls/id/MAPG-8NVRPY
http://osvdb.org/80226
http://secunia.com/advisories/48403
http://secunia.com/advisories/48453
Common Vulnerability Exposure (CVE) ID: CVE-2012-1842
http://osvdb.org/80225
http://osvdb.org/80239
Common Vulnerability Exposure (CVE) ID: CVE-2012-1844
http://www.kb.cert.org/vuls/id/MORO-8QNJLE
http://osvdb.org/80372
XForce ISS Database: scalar-default-account(74322)
https://exchange.xforce.ibmcloud.com/vulnerabilities/74322
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.