PoC Index

CVE-2010-3274

MEDIUM 4.3EPSS 21.0%

Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString parameter in a (1) showList or (2) Search action.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
21.00% chance of exploitation in the next 30 days, 97th percentile
Published
2011-02-17
Updated
2024-08-07

ExploitDB entries (1)

References

Related