← Back

CVE-2011-0552

nvd nist
Published: Oct 2, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec IM Manager before 8.4.18 allow remote attackers to inject arbitrary web script or HTML via the (1) refreshRateSetting parameter to IMManager/Admin/IMAdminSystemDashboard.asp, the (2) nav or (3) menuitem parameter to IMManager/Admin/IMAdminTOC_simple.asp, or the (4) action parameter to IMManager/Admin/IMAdminEdituser.asp.

Affected (20)

Products: Symantec: Im Manager
1 product
Im Manager
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Symantec
Up to 8.4.17
Version 6.0
Version 6.5
Version 7.0
Version 7.5
Version 8.3
Version 8.4.0
Version 8.4.10
Version 8.4.11
Version 8.4.12
Version 8.4.13
Version 8.4.15
Version 8.4.16
Version 8.4.1
Version 8.4.2
Version 8.4.5
Version 8.4.6
Version 8.4.7
Version 8.4.8
Version 8.4.9

Timeline

No history available yet.