CVE-2012-4891
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.9%
from disclosure to weapon871 days
Published on NVDSep 10
1st PoC+871d
exploitation probability
3.9%top 11% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/35933unverifiedcve_referencepacketstormsecurity.com/files/130169/ManageEngine-Firewall-Analyzer-8.0-Directory-Traversal-XSS.htmlunverifiedcve_referencewww.exploit-db.com/exploits/35933unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.