4.3
CVSSv2

CVE-2012-1990

Published: 22/05/2012 Updated: 15/05/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb prior to 3.0.1 and Kerwin prior to 6.0.1 allow remote malicious users to inject arbitrary web script or HTML via (1) the evtvariablename parameter in an evts.xml action to kw.dll, (2) unspecified search fields, or (3) unspecified content-display fields.

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric kerwin

schneider-electric kerweb

Exploits

source: wwwsecurityfocuscom/bid/53409/info Multiple Schneider Electric Telecontrol products are prone to an HTML-injection vulnerability because they fail to sufficiently sanitize user-supplied data before it is used in dynamic content Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially a ...
Kerweb versions prior to 301 and Kerwin versions prior to 601 suffer from multiple cross site scripting vulnerabilities ...