Lucene search

K
cveMitreCVE-2012-6514
HistoryJan 24, 2013 - 1:55 a.m.

CVE-2012-6514

2013-01-2401:55:05
CWE-79
mitre
web.nvd.nist.gov
27
cve-2012-6514
cross-site scripting
xss
nbill component
joomla
security vulnerability
web script injection
html injection
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.002

Percentile

58.6%

Cross-site scripting (XSS) vulnerability in the nBill (com_nbill) component 2.3.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the message parameter in an income action to administrator/index.php.

Affected configurations

Nvd
Node
netshinesoftwarecom_netinvoiceMatch2.3.2
AND
joomlajoomla\!
VendorProductVersionCPE
netshinesoftwarecom_netinvoice2.3.2cpe:2.3:a:netshinesoftware:com_netinvoice:2.3.2:*:*:*:*:*:*:*
joomlajoomla\!*cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.002

Percentile

58.6%

Related for CVE-2012-6514