ESET Remote Administrator < 3.0.105 Additional Report Settings XSS

This script is Copyright (C) 2009-2013 Tenable Network Security, Inc.


Synopsis :

The remote Windows host contains an application that is affected by an
HTML injection vulnerability.

Description :

ESET Remote Administrator is installed on the remote system. The
installed version is less than version 3.0.105, and such versions are
reportedly affected by an HTML injection vulnerability. An attacker can
exploit this vulnerability to cause arbitrary HTML and script code to be
executed with in the context of the user's browser.

See also :

http://www.eset.eu/support/changelog-eset-remote-administrator-3

Solution :

Upgrade to version 3.0.105.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.6
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 35611 (eset_ra_3_0_105_html_injection.nasl)

Bugtraq ID: 33633

CVE ID: