| Solutionary ID: SERT-VDN-1003 |
| CVE ID: CVE-2011-3684 |
| Product: Tembria Server Monitor |
| Application Vendor: Tembria |
| Vendor URL: http://www.tembria.com/products/servermonitor/index.html |
| Date discovered: 1/22/2011 |
| Discovered by: Rob Kraus, Jose Hernandez, and Solutionary Engineering Research Team (SERT) |
| Vendor notification date: 1/25/2011 |
| Vendor response date: 1/25/2011 |
| Vendor acknowledgment date: 1/25/2011 |
Public disclosure date: 2/14/2011 Exploit Vectors: Local and Remote event-history.asp (siteid, type) parameter Tested on: Windows XP, SP3, with Tembria Server Monitor v6.0.4 - Build 2229 default installation. Affected software versions: Tembria Server Monitor v6.0.4 - Build 2229 (previous versions may also be vulnerable) Impact: Successful attacks could disclose sensitive information about the user, session, and application to the attacker, resulting in a loss of confidentiality. Using XSS, an attacker could insert malicious code into a web page and entice naïve users to execute the malicious code. Fixed in: Tembria Server Monitor v6.0.5 - Build 2252 Remediation guidelines: The vendor has created a fix for the vulnerabilities identified. Please update to version 6.0.5 - Build 2252 or newer. |
- Trusted Managed Security Provider | Solutionary
- Research
- Vulnerability Disclosures
- Tembria Server Monitor Multiple Cross-site Scripting (XSS) Vulnerabilities

