7.5
CVSSv2

CVE-2012-6637

Published: 03/03/2014 Updated: 03/03/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions do not anchor the end of domain-name regular expressions, which allows remote malicious users to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring.

Vulnerable Product Search on Vulmon Subscribe to Product

apache cordova 3.3.0

apache cordova 3.2.0

apache cordova

apache cordova 3.0.0

apache cordova 3.1.0

adobe phonegap 2.0.0

adobe phonegap 2.1.0

adobe phonegap 2.7.0

adobe phonegap 2.2.0

adobe phonegap 2.3.0

adobe phonegap 2.5.0

adobe phonegap 2.6.0

adobe phonegap 2.9.0

adobe phonegap 2.4.0

adobe phonegap

adobe phonegap 2.8.0

adobe phonegap 2.8.1