Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-4533
HistoryNov 19, 2012 - 12:00 a.m.

CVE-2012-4533

2012-11-1900:00:00
ubuntu.com
ubuntu.com
16

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

50.9%

Cross-site scripting (XSS) vulnerability in the “extra” details in the
DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13
and 1.1.x before 1.1.16 allows remote authenticated users with repository
commit access to inject arbitrary web script or HTML via the “function
name” line.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchviewvc< 1.1.5-1.1+squeeze2build0.12.04.1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

50.9%