Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-1097

EPSS 0.68% · P72
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-1097

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onload event.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Novell ZENworks Configuration Management 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Novell ZENworks Configuration Management(ZCM)是美国Novell公司的一套配置管理解决方案。该方案可借助集成工具,在物理、虚拟和云环境中实现IT管理和业务流程的自动化。 Novell ZENworks Configuration Management (ZCM) 11.2.3a Monthly Update 1之前的11.2版本中的njwc.jar中的ZCC页面中存在跨站脚本漏洞。远程攻击者可通过包含onload事件的向量利用该漏洞注入任意Web脚本或HTML。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-1097

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-1097

Please Login to view more intelligence information

Same Patch Batch · n/a · 2013-06-17 · 21 CVEs total

CVE-2013-4609REDCap 权限许可和访问控制问题漏洞
CVE-2013-3643Android平台的Galapagos Browser应用程序信息泄露漏洞
CVE-2013-3642Android平台的Angel Browser应用程序信息泄露漏洞
CVE-2013-3520VMware vCenter Chargeback Manager 代码注入漏洞
CVE-2013-3026IBM Lotus Quickr for Domino ActiveX Control 缓冲区溢出漏洞
CVE-2013-2310SoftBank Wi-Fi Spot Configuration Software 信息泄露漏洞
CVE-2013-2309OpenPNE 跨站脚本漏洞
CVE-2013-4612REDCap 多个跨站脚本漏洞
CVE-2013-4611REDCap 多个安全漏洞
CVE-2013-4610REDCap 数据输入表单Data Search工具安全漏洞
CVE-2012-6564REDCap 跨站脚本漏洞
CVE-2013-4608REDCap 跨站脚本漏洞
CVE-2013-2981IBM Data Studio 目录遍历漏洞
CVE-2013-2980IBM Data Studio Web Console 跨站请求伪造漏洞
CVE-2013-1095Novell ZENworks Configuration Management 反射XSS跨站脚本漏洞
CVE-2013-1094Novell ZENworks Configuration Management 跨站脚本漏洞
CVE-2013-1093Novell ZENworks Configuration Management 开放重定向漏洞
CVE-2012-6567REDCap 输入验证漏洞
CVE-2012-6566REDCap 跨站脚本漏洞
CVE-2012-6565REDCap 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2013-1097

No comments yet


Leave a comment