Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.103556
Category:Web application abuses
Title:op5 Monitor <= 5.4.2 Multiple Vulnerabilities
Summary:op5 Monitor is prone to an HTML injection vulnerability and an; SQL injection (SQLi) vulnerability because it fails to sanitize user-supplied input.
Description:Summary:
op5 Monitor is prone to an HTML injection vulnerability and an
SQL injection (SQLi) vulnerability because it fails to sanitize user-supplied input.

Vulnerability Impact:
Exploiting these issues may allow an attacker to compromise the
application, access or modify data, exploit vulnerabilities in the underlying database, execute
HTML and script code in the context of the affected site, steal cookie-based authentication
credentials, or control how the site is rendered to the user, other attacks are also possible.

Affected Software/OS:
op5 Monitor version 5.4.2 is known to be vulnerable. Other
versions may also be affected.

Solution:
Vendor updates are available. Please see the references for
more information.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:P/A:N

CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.