4.3
CVSSv2

CVE-2012-1208

Published: 24/02/2012 Updated: 24/02/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions prior to 3.2.5 allow remote malicious users to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or (2) error parameter to users/index.

Vulnerable Product Search on Vulmon Subscribe to Product

fork-cms fork cms 3.2.4

Exploits

########################################################################################################################## # Exploit Title: Fork CMS v324 - Multiple Vulnerabilities # Script Page : wwwfork-cmscom # Date: 11-02-2012 # Author : RandomStorm - wwwrandomstormcom # Avram Marius Gab ...
+--------------------------------------------------------------------------------------------- ...