4.3
CVSSv2

CVE-2012-5851

Published: 15/11/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote malicious users to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome 22.0.1229.94

google chrome 22.0.1229.65

google chrome 22.0.1229.67

google chrome 22.0.1229.21

google chrome 22.0.1229.22

google chrome 22.0.1229.29

google chrome 22.0.1229.31

google chrome 22.0.1229.48

google chrome 22.0.1229.39

google chrome 22.0.1229.56

google chrome 22.0.1229.55

google chrome 22.0.1229.7

google chrome 22.0.1229.8

google chrome 22.0.1229.10

google chrome 22.0.1229.91

google chrome 22.0.1229.92

google chrome 22.0.1229.58

google chrome 22.0.1229.59

google chrome 22.0.1229.18

google chrome 22.0.1229.20

google chrome 22.0.1229.27

google chrome 22.0.1229.28

google chrome 22.0.1229.37

google chrome 22.0.1229.36

google chrome 22.0.1229.54

google chrome 22.0.1229.53

google chrome 22.0.1229.4

google chrome 22.0.1229.6

google chrome 22.0.1229.79

google chrome 22.0.1229.89

google chrome 22.0.1229.95

google chrome 22.0.1229.60

google chrome 22.0.1229.62

google chrome 22.0.1229.16

google chrome 22.0.1229.17

google chrome 22.0.1229.25

google chrome 22.0.1229.26

google chrome 22.0.1229.35

google chrome 22.0.1229.33

google chrome 22.0.1229.52

google chrome 22.0.1229.51

google chrome 22.0.1229.2

google chrome 22.0.1229.3

google chrome 22.0.1229.0

apple webkit

google chrome

google chrome 22.0.1229.63

google chrome 22.0.1229.64

google chrome 22.0.1229.76

google chrome 22.0.1229.78

google chrome 22.0.1229.12

google chrome 22.0.1229.14

google chrome 22.0.1229.23

google chrome 22.0.1229.24

google chrome 22.0.1229.49

google chrome 22.0.1229.32

google chrome 22.0.1229.57

google chrome 22.0.1229.50

google chrome 22.0.1229.9

google chrome 22.0.1229.1

google chrome 22.0.1229.11

apple safari 5.1.7

Exploits

source: wwwsecurityfocuscom/bid/56570/info WebKit is prone to a security-bypass vulnerability An attacker can exploit this vulnerability to bypass the cross-site scripting filter mechanism Successful exploits may allow attackers to execute arbitrary script code and steal cookie-based authentication credentials Code in testjsp: &lt ...