Lucene search

K
cveMitreCVE-2012-1208
HistoryFeb 24, 2012 - 1:55 p.m.

CVE-2012-1208

2012-02-2413:55:07
CWE-79
mitre
web.nvd.nist.gov
24
cve
2012
1208
xss
vulnerabilities
fork cms
3.2.4

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.01

Percentile

83.8%

Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or (2) error parameter to users/index.

Affected configurations

Nvd
Node
fork-cmsfork_cmsMatch3.2.4
VendorProductVersionCPE
fork-cmsfork_cms3.2.4cpe:2.3:a:fork-cms:fork_cms:3.2.4:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.01

Percentile

83.8%

Related for CVE-2012-1208