2.6
CVSSv2

CVE-2011-2712

Published: 29/08/2011 Updated: 09/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x prior to 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote malicious users to inject arbitrary web script or HTML via unspecified parameters.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache wicket 1.4.3

apache wicket 1.4.4

apache wicket 1.4.11

apache wicket 1.4.12

apache wicket 1.4.1

apache wicket 1.4.2

apache wicket 1.4.9

apache wicket 1.4.10

apache wicket 1.4.5

apache wicket 1.4.6

apache wicket 1.4.13

apache wicket 1.4.14

apache wicket 1.4.0

apache wicket 1.4.7

apache wicket 1.4.8

apache wicket 1.4.15

apache wicket 1.4.16

apache wicket 1.4.17

Github Repositories

Creating proof of concepts for some old CVEs

Vulnerability Research CVEs CVE-2018-6184 CVE-2011-2712 CVE-2018-3778 CVE-2018-1002204 Bonus Nextjs LFI