Release date: 2012-09-04
Updated on: 2012-09-07
Affected Systems:
Ipswitch WhatsUp Gold 15.0.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55393
Cve id: CVE-2012-2589
WhatsUp Gold provides a complete and easy-to-use monitoring mechanism to comprehensively monitor application services and network devices, and helps IT administrators transform Network Management Information into readable business information.
WhatsUp Gold 15.0.2 and other versions have the HTML injection vulnerability, which can cause attackers to run HTML or JS code on the affected site, steal Cookie authentication creden。, and control the appearance of the site.
<* Source: Devon Kearns
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ipswitch
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ipswitch.com/