CVE-2012-5956
CVE-2012-5956 is a medium-severity vulnerability in Zohocorp Manageengine Assetexplorer with a CVSS 2.0 base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-79.
Key facts
- Severity: Medium (CVSS 2.0 base score 4.3)
- EPSS exploit prediction: 4% (90th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-79
- Affected product: Zohocorp Manageengine Assetexplorer
- Published:
- Last modified:
Description
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine AssetExplorer 5.6 before service pack 5614 allow remote attackers to inject arbitrary web script or HTML via fields in XML asset data to discoveryServlet/WsDiscoveryServlet, as demonstrated by the DocRoot/Computer_Information/output element.
Frequently asked questions
- What is CVE-2012-5956?
- Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine AssetExplorer 5.6 before service pack 5614 allow remote attackers to inject arbitrary web script or HTML via fields in XML asset data to discoveryServlet/WsDiscoveryServlet, as demonstrated by the DocRoot/Computer_Information/output element.
- How severe is CVE-2012-5956?
- CVE-2012-5956 has a CVSS 2.0 base score of 4.3, rated medium severity.
- Is CVE-2012-5956 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 4% (90th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2012-5956?
- CVE-2012-5956 affects Zohocorp Manageengine Assetexplorer. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2012-5956?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2012-5956 published?
- CVE-2012-5956 was published on 2012-12-11 and last updated on 2026-06-16.
References
- http://www.kb.cert.org/vuls/id/571068
- http://www.manageengine.com/products/asset-explorer/sp-readme.html
Affected products (1)
- cpe:2.3:a:zohocorp:manageengine_assetexplorer:*:5613:*:*:*:*:*:*
More vulnerabilities in Zohocorp Manageengine Assetexplorer
- CVE-2022-47966 — Critical (CVSS 9.8): Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due…
- CVE-2021-20110 — Critical (CVSS 9.8): Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can…
- CVE-2019-12994 — Critical (CVSS 9.1): Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet…
- CVE-2019-12959 — High (CVSS 8.8): Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet…
- CVE-2019-14693 — High (CVSS 8.5): Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing…
- CVE-2023-35785 — High (CVSS 8.1): Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and…
All CVEs affecting Zohocorp Manageengine Assetexplorer →
Other CWE-79 (Cross-site Scripting (XSS)) vulnerabilities
- CVE-2026-106102 — Critical (CVSS 10.0): Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only…
- CVE-2026-59167 — Critical (CVSS 10.0): SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11,…
- CVE-2026-85061 — Critical (CVSS 10.0): MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in…
- CVE-2025-49410 — Critical (CVSS 10.0): Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC…
- CVE-2024-47875 — Critical (CVSS 10.0): DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to…
- CVE-2024-6886 — Critical (CVSS 10.0): Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea…
Browse all CWE-79 (Cross-site Scripting (XSS)) vulnerabilities →