| Solutionary ID: SERT-VDN-1001 |
| CVE ID: CVE-2010-4841 |
| Product: ManageEngine EventLog Analyzer version 6.1 |
| Application Vendor: ManageEngine |
| Vendor URL: http://www.manageengine.com/products/eventlog/ |
| Date discovered: 9/15/2010 |
| Discovered by: Rob Kraus, Jose Hernandez, and Solutionary Engineering Research Team (SERT) |
| Vendor notification date: 10/26/2010 |
| Vendor response date: 11/12/2010 |
| Vendor acknowledgment date: 12/2/2010 |
Public disclosure date: 12/10/2010 Exploit Vectors: Local and Remote INDEX.do (HOST_ID, OS, GROUP, exportFile, load, type, tab) parameters Tested on: Windows XP, SP1, with EventLog Analyzer version 6.1 default installation. Affected software versions: ManageEngine EventLog Analyzer version 6.1 (previous versions may also be vulnerable) |
- Trusted Managed Security Provider | Solutionary
- Research
- Vulnerability Disclosures
- ManageEngine EventLog Analyzer Multiple Cross-site Scripting (XSS) Vulnerabilities

