4.3
CVSSv2

CVE-2012-4437

Published: 01/10/2012 Updated: 16/11/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) prior to 3.1.12 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.

Vulnerable Product Search on Vulmon Subscribe to Product

smarty smarty 2.6.10

smarty smarty 2.6.17

smarty smarty 2.6.7

smarty smarty 3.1.1

smarty smarty 2.6.13

smarty smarty 2.6.0

smarty smarty 2.6.11

smarty smarty 1.5.1

smarty smarty 2.4.1

smarty smarty 2.4.0

smarty smarty 2.6.25

smarty smarty 1.0

smarty smarty 3.1.8

smarty smarty 2.6.18

smarty smarty 3.0.0

smarty smarty 1.4.3

smarty smarty 1.4.4

smarty smarty 3.0.1

smarty smarty 1.1.0

smarty smarty 1.2.1

smarty smarty 3.1.3

smarty smarty 3.1.2

smarty smarty 3.1.6

smarty smarty 2.6.9

smarty smarty 2.6.16

smarty smarty 2.6.14

smarty smarty 2.6.12

smarty smarty 2.0.0

smarty smarty 1.5.0

smarty smarty 1.5.2

smarty smarty 2.3.1

smarty smarty 2.6.24

smarty smarty 3.1.7

smarty smarty 3.1.0

smarty smarty 3.0.6

smarty smarty 3.0.7

smarty smarty 1.4.0

smarty smarty 1.4.1

smarty smarty 1.0b

smarty smarty 1.2.0

smarty smarty 2.6.22

smarty smarty 3.1.5

smarty smarty 2.6.1

smarty smarty 3.1.4

smarty smarty 2.6.3

smarty smarty 2.6.4

smarty smarty 2.6.5

smarty smarty 2.6.6

smarty smarty 2.6.15

smarty smarty 2.0.1

smarty smarty 2.1.0

smarty smarty 2.1.1

smarty smarty 1.4.6

smarty smarty 2.6.26

smarty smarty 1.0a

smarty smarty 3.1

smarty smarty 1.4.2

smarty smarty 1.2.2

smarty smarty 1.3.0

smarty smarty 1.3.1

smarty smarty 1.3.2

smarty smarty 2.6.2

smarty smarty 3.0.4

smarty smarty 3.0.3

smarty smarty 3.0.2

smarty smarty 2.5.0

smarty smarty 2.6.20

smarty smarty 2.4.2

smarty smarty 2.2.0

smarty smarty 2.3.0

smarty smarty 3.1.9

smarty smarty 3.1.10

smarty smarty 3.1.11

smarty smarty 3.0.5

smarty smarty 1.4.5

Vendor Advisories

Debian Bug report logs - #688153 [CVE-2012-4437] XSS in Smarty exception messages Package: smarty3; Maintainer for smarty3 is Mike Gabriel <sunweaver@debianorg>; Source for smarty3 is src:smarty3 (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: Wed, 19 Sep 2012 20:57:01 UTC Severity: grav ...