4.3
CVSSv2

CVE-2014-3738

Published: 20/05/2014 Updated: 01/08/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote malicious users to inject arbitrary web script or HTML via the title of a device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zenoss zenoss 4.2.5

Exploits

# Exploit Title: Stored XSS vulnerability in Zenoss core open source monitoring system # Date: 12/05/2014 # Exploit author: Dolev Farhi dolev(at)openflareorg # Vendor homepage: zenosscom # Software Link: wwwzenosscom # Version: Core 425-2108 64bit # Tested on: Kali Linux # Vendor alerted: 12/05/2014 # CVE-2014-3738 Software det ...
Zenoss Monitoring System version 425-2108 64-bit suffers from a persistent cross site scripting vulnerability ...