Lucene search

K
nvd[email protected]NVD:CVE-2012-3837
HistoryJul 03, 2012 - 10:55 p.m.

CVE-2012-3837

2012-07-0322:55:02
CWE-79
web.nvd.nist.gov

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.4%

Multiple cross-site scripting (XSS) vulnerabilities in apps/users/registration.template.php in Baby Gekko 1.2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email_address, (3) password, (4) password_verify, (5) firstname, (6) lastname, or (7) verification_code parameter to users/action/register. NOTE: some of these details are obtained from third party information.

Affected configurations

NVD
Node
babygekkobaby_gekkoRange1.2.0
OR
babygekkobaby_gekkoMatch0.90
OR
babygekkobaby_gekkoMatch0.91
OR
babygekkobaby_gekkoMatch0.98alpha
OR
babygekkobaby_gekkoMatch0.99beta
OR
babygekkobaby_gekkoMatch1.0.0
OR
babygekkobaby_gekkoMatch1.0.1
OR
babygekkobaby_gekkoMatch1.1.0
OR
babygekkobaby_gekkoMatch1.1.1
OR
babygekkobaby_gekkoMatch1.1.2
OR
babygekkobaby_gekkoMatch1.1.3
OR
babygekkobaby_gekkoMatch1.1.4
OR
babygekkobaby_gekkoMatch1.1.5

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.4%

Related for NVD:CVE-2012-3837