4.3
CVSSv2

CVE-2012-1039

Published: 19/03/2012 Updated: 11/01/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 450
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Dotclear prior to 2.4.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

dotclear dotclear 1.2.8

dotclear dotclear 1.2.7

dotclear dotclear 2.0

dotclear dotclear 1.2.2

dotclear dotclear 1.2.5

dotclear dotclear 2.2.1

dotclear dotclear 2.3.0

dotclear dotclear 2.0.1

dotclear dotclear 2.0.2

dotclear dotclear 1.2.6

dotclear dotclear 1.2.3

dotclear dotclear 2.1.3

dotclear dotclear 2.1.7

dotclear dotclear 1.2.4

dotclear dotclear 2.2.2

dotclear dotclear 2.2

dotclear dotclear 2.1.5

dotclear dotclear 2.1.1

dotclear dotclear 2.1

dotclear dotclear 1.2.1

dotclear dotclear 2.1.4

dotclear dotclear 2.2.3

dotclear dotclear 2.1.6

dotclear dotclear

Exploits

Dotclear version 2412 suffers from multiple cross site scripting vulnerabilities ...
source: wwwsecurityfocuscom/bid/52221/info Dotclear is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may let the atta ...
source: wwwsecurityfocuscom/bid/52221/info Dotclear is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may let the at ...
source: wwwsecurityfocuscom/bid/52221/info Dotclear is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may let the ...
source: wwwsecurityfocuscom/bid/52221/info Dotclear is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may let the attack ...