Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.
2012-10-31T19:55:00.950
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | solarwinds | ip_address_manager_web_interface | ≤ 3.0 | Yes |
Application | solarwinds | orion_network_performance_monitor | - | Yes |
Application | solarwinds | orion_network_performance_monitor | 10.0 | Yes |
Application | solarwinds | orion_network_performance_monitor | 10.1 | Yes |
Application | solarwinds | orion_network_performance_monitor | 10.1.13.0 | Yes |
Application | solarwinds | orion_network_performance_monitor | 10.2 | Yes |
Application | solarwinds | orion_network_performance_monitor | 10.2.1 | Yes |
Application | solarwinds | orion_network_performance_monitor | 10.2.2 | Yes |
Application | solarwinds | orion_network_performance_monitor | 10.3 | Yes |
Application | solarwinds | orion_network_performance_monitor | 10.3.1 | Yes |