4.3
CVSSv2

CVE-2012-0974

Published: 25/09/2012 Updated: 15/10/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass prior to 2.3.5 allow remote malicious users to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and (4) sPriceMin parameters in a search action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

juan ramon osclass 2.0.1

juan ramon osclass 2.0

juan ramon osclass 1.2

juan ramon osclass 2.3

juan ramon osclass 2.2.3

juan ramon osclass 2.2.2

juan ramon osclass 2.2.1

juan ramon osclass 2.2

juan ramon osclass 2.3.3

juan ramon osclass 2.3.1

juan ramon osclass 2.1

juan ramon osclass 2.0.2

juan ramon osclass 1.1

juan ramon osclass

juan ramon osclass 2.3.2

juan ramon osclass 2.1.1

juan ramon osclass 2.0.3

Exploits

source: wwwsecurityfocuscom/bid/51662/info OSClass is prone to SQL-injection and cross-site scripting vulnerabilities Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database ...