CVE-2012-0040: XSS
Published Jan 24, 2012
·Updated
Cross-site scripting (XSS) vulnerability in modules/core/www/nocookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.
Affected Software
16 affected components
SimpleSAMLphp<=1.8.1
SimpleSAMLphp=0.4
SimpleSAMLphp=0.5
SimpleSAMLphp=1.0
SimpleSAMLphp=1.1
SimpleSAMLphp=1.2
SimpleSAMLphp=1.3
SimpleSAMLphp=1.4
SimpleSAMLphp=1.5
SimpleSAMLphp=1.5.1
SimpleSAMLphp=1.6
SimpleSAMLphp=1.6.1
SimpleSAMLphp=1.6.2
SimpleSAMLphp=1.6.3
SimpleSAMLphp=1.7
SimpleSAMLphp=1.8
Event History
Jan 24, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0040?
CVE-2012-0040 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2012-0040?
To fix CVE-2012-0040, upgrade SimpleSAMLphp to version 1.8.2 or later.
3
Which versions are affected by CVE-2012-0040?
CVE-2012-0040 affects SimpleSAMLphp versions prior to 1.8.2, including all versions from 0.4 to 1.8.1.
4
Can CVE-2012-0040 lead to data theft?
Yes, CVE-2012-0040 can potentially allow attackers to inject malicious scripts that may result in data theft.
5
Is there a public exploit for CVE-2012-0040?
While there may not be a specific public exploit, the vulnerability allows for XSS attacks, which can be used by attackers in various ways.