Microsoft System Center Configuration Manager Cross Site Scripting

Strike ID:
E12-4yg01
CVSS:
4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
False Positive:
f
Variants:
1
Year:
2012

Description

This strike exploits a reflected cross-site scripting (XSS) vulnerability in Microsoft System Center Configuration Manager. The vulnerability is caused by lack of input validation when handling HTTP requests. This vulnerability can be exploited by an attacker to execute malicious code in in the context of the victim user's browser.

CVE

Bid