Lucene search

K
cveMitreCVE-2012-4890
HistorySep 10, 2012 - 10:55 p.m.

CVE-2012-4890

2012-09-1022:55:07
CWE-79
mitre
web.nvd.nist.gov
36
cve
2012
4890
flatnux cms
xss
vulnerabilities
remote
injection
web script
html
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.004

Percentile

72.9%

Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2011 08.09.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) comment to the news, (2) title to the news, or (3) the folder names in a gallery.

Affected configurations

Nvd
Node
flatnuxflatnuxRange2011-08-09-2
OR
flatnuxflatnuxMatch2008-12-11
OR
flatnuxflatnuxMatch2009-01-27
OR
flatnuxflatnuxMatch2009-02-04
VendorProductVersionCPE
flatnuxflatnux*cpe:2.3:a:flatnux:flatnux:*:*:*:*:*:*:*:*
flatnuxflatnux2008-12-11cpe:2.3:a:flatnux:flatnux:2008-12-11:*:*:*:*:*:*:*
flatnuxflatnux2009-01-27cpe:2.3:a:flatnux:flatnux:2009-01-27:*:*:*:*:*:*:*
flatnuxflatnux2009-02-04cpe:2.3:a:flatnux:flatnux:2009-02-04:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.004

Percentile

72.9%

Related for CVE-2012-4890