This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.
A web application on the remote host is affected by a
cross-site scripting vulnerability.
The remote ManageEngine ADSelfService Plus install is affected by
a cross-site scripting vulnerability. The application does not
properly sanitize the 'searchString' and 'searchType' parameters on
the page 'EmployeeSearch.cc'.
A remote attacker could exploit this by tricking a user
into requesting a maliciously crafted URL. Exploitation could also
allow the attacker to steal cookie-based authentication credentials.
See also :
There is currently no patch available from the vendor.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.6
Public Exploit Available : true
Family: CGI abuses : XSS
Nessus Plugin ID: 57049 ()
Bugtraq ID: 4633150717
CVE ID: CVE-2010-3274CVE-2011-5105
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.