Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2021-25932
Disclosure Date: June 01, 2021 (last updated November 28, 2024)
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function `validateFormInput()` performs improper validation checks on the input sent to the `userID` parameter. Due to this flaw an attacker could inject an arbitrary script which will be stored in the database.
0
Attacker Value
Unknown
CVE-2020-1652
Disclosure Date: July 08, 2020 (last updated November 28, 2024)
OpenNMS is accessible via port 9443
0
Attacker Value
Unknown
CVE-2020-12760
Disclosure Date: May 11, 2020 (last updated October 06, 2023)
An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code execution for any authenticated channel user regardless of its assigned permissions.
0
Attacker Value
Unknown
CVE-2016-6556
Disclosure Date: September 14, 2016 (last updated November 29, 2024)
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent supplied data. By creating a malicious SNMP 'sysName' or 'sysContact' response, an attacker can store an XSS payload which will trigger when a user of the web UI views the data. This issue was fixed in version 18.0.2, released on September 20, 2016.
0
Attacker Value
Unknown
CVE-2016-6555
Disclosure Date: September 14, 2016 (last updated November 29, 2024)
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in version 18.0.2, released on September 20, 2016.
0
Attacker Value
Unknown
CVE-2015-7856
Disclosure Date: October 16, 2015 (last updated October 05, 2023)
OpenNMS has a default password of rtc for the rtc account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.
0
Attacker Value
Unknown
CVE-2014-3960
Disclosure Date: June 04, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.12.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-0936
Disclosure Date: January 29, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java in OpenNMS 1.8.x before 1.8.17, 1.9.93 and earlier, and 1.10.x before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via the Username field, related to login.
0
Attacker Value
Unknown
CVE-2008-6095
Disclosure Date: February 09, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in surveillanceView.htm in OpenNMS 1.5.94 allows remote attackers to inject arbitrary web script or HTML via the viewName parameter.
0
Attacker Value
Unknown
CVE-2008-4320
Disclosure Date: September 29, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary web script or HTML via (1) the j_username parameter to j_acegi_security_check, (2) the username parameter to notification/list.jsp, and (3) the filter parameter to event/list.
0