Description
|
|
(#Several vulnerabilities were reported in Infoblox Network Automation:#- cross-site scripting located in parameters "_formStack", "skipjackPassword" and "skipjackUsername" of the "netmri/config/userAdmin/login.tdf" web page##- cross-site scripting located in parameters "DefaultTitle", "defaultAccordion", "defaultMenu" and "defaultPage" of the "netmri/config/index.tdf" web page##- cross-site scripting located in the "helpId" parameter of the "netmri/help/netmri_help/netmri_help.tdf" web page##- CVE-2016-6484: CRLF injection / HTTP splitting located in the "contentType" parameter of the login page of netmri ("netmri/config/userAdmin/login.tdf").##Proofs of concept are available.)
|