Lucene search

K
cvelistCertccCVELIST:CVE-2012-2578
HistorySep 19, 2012 - 10:00 a.m.

CVE-2012-2578

2012-09-1910:00:00
certcc
www.cve.org
4
smartermail 9.2
cross-site scripting
remote attackers
web script
html
e-mail message body
javascript alert function
fromcharcode method
script element
cascading style sheets
css expression property
innerhtml attribute
xml document

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

53.5%

Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a JavaScript alert function used in conjunction with the fromCharCode method, (2) a SCRIPT element, (3) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an arbitrary element, or (4) an innerHTML attribute within an XML document.

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

53.5%

Related for CVELIST:CVE-2012-2578