← All CVEs

CVE-2012-2577

medium · 4.3

Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.

4.3
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2012-08-12
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
solarwindsorion_network_performance_monitor<= 10.2
solarwindsorion_network_performance_monitor7.8.5
solarwindsorion_network_performance_monitor8.5
solarwindsorion_network_performance_monitor8.5.1
solarwindsorion_network_performance_monitor9.0
solarwindsorion_network_performance_monitor9.1
solarwindsorion_network_performance_monitor9.5.1
solarwindsorion_network_performance_monitor10.0
solarwindsorion_network_performance_monitor10.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-2577