2.6
CVSSv2

CVE-2012-4037

Published: 15/08/2012 Updated: 22/02/2013
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission prior to 2.61 allow remote malicious users to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file.

Vulnerable Product Search on Vulmon Subscribe to Product

transmissionbt transmission 1.93

transmissionbt transmission 1.90

transmissionbt transmission 1.83

transmissionbt transmission 0.72

transmissionbt transmission 0.6.1

transmissionbt transmission 1.76

transmissionbt transmission 1.10

transmissionbt transmission 1.04

transmissionbt transmission 0.96

transmissionbt transmission 1.22

transmissionbt transmission 0.91

transmissionbt transmission 1.71

transmissionbt transmission 1.72

transmissionbt transmission 1.33

transmissionbt transmission 1.40

transmissionbt transmission 2.01

transmissionbt transmission 2.02

transmissionbt transmission 2.21

transmissionbt transmission 2.22

transmissionbt transmission 2.42

transmissionbt transmission 2.50

transmissionbt transmission 1.80

transmissionbt transmission 1.77

transmissionbt transmission 0.90

transmissionbt transmission 0.80

transmissionbt transmission 0.6

transmissionbt transmission 0.3

transmissionbt transmission 1.11

transmissionbt transmission 1.74

transmissionbt transmission 1.91

transmissionbt transmission 0.81

transmissionbt transmission 0.71

transmissionbt transmission 0.4

transmissionbt transmission 0.1

transmissionbt transmission 0.2

transmissionbt transmission 1.02

transmissionbt transmission 1.05

transmissionbt transmission 0.92

transmissionbt transmission 1.51

transmissionbt transmission 0.93

transmissionbt transmission 1.70

transmissionbt transmission 1.54

transmissionbt transmission 1.32

transmissionbt transmission 1.31

transmissionbt transmission 2.00

transmissionbt transmission 2.13

transmissionbt transmission 2.20

transmissionbt transmission 1.92

transmissionbt transmission 1.81

transmissionbt transmission 1.82

transmissionbt transmission 0.82

transmissionbt transmission 0.70

transmissionbt transmission 0.5

transmissionbt transmission 1.06

transmissionbt transmission 1.20

transmissionbt transmission 0.95

transmissionbt transmission 1.01

transmissionbt transmission 1.52

transmissionbt transmission 1.34

transmissionbt transmission 1.73

transmissionbt transmission 1.42

transmissionbt transmission 1.41

transmissionbt transmission 1.21

transmissionbt transmission 2.03

transmissionbt transmission 2.04

transmissionbt transmission 2.10

transmissionbt transmission 2.30

transmissionbt transmission 2.31

transmissionbt transmission 2.51

transmissionbt transmission 2.52

transmissionbt transmission 1.03

transmissionbt transmission 1.00

transmissionbt transmission 1.50

transmissionbt transmission 0.94

transmissionbt transmission 1.75

transmissionbt transmission 1.60

transmissionbt transmission 1.53

transmissionbt transmission 1.61

transmissionbt transmission 1.2

transmissionbt transmission 1.30

transmissionbt transmission 2.11

transmissionbt transmission 2.12

transmissionbt transmission 2.32

transmissionbt transmission 2.33

transmissionbt transmission

transmissionbt transmission 2.40

transmissionbt transmission 2.41

Vendor Advisories

Debian Bug report logs - #683380 CVE-2012-4037 Package: transmission; Maintainer for transmission is Sandro Tosi <morph@debianorg>; Source for transmission is src:transmission (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Tue, 31 Jul 2012 09:45:04 UTC Severity: grave Tags: ...
Transmission could be made to expose sensitive information over the network ...

Exploits

Transmission BitTorrent client versions prior to 261 suffer from a cross site scripting vulnerability ...