4.3
CVSSv2

CVE-2012-3232

Published: 29/06/2012 Updated: 02/07/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in search.php in web@all 2.0, as downloaded before May 30, 2012, allows remote malicious users to inject arbitrary web script or HTML via the _text[title] parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

webatall web\\@all 2.0

Exploits

Web@All version 20 suffers from cross site request forgery and cross site scripting vulnerabilities ...
source: wwwsecurityfocuscom/bid/54109/info web@all is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication cr ...