CVE-2012-0311: XSS
Published Jan 26, 2012
·Updated
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
8 affected components
osCommerce oscommerce=2.2ms1j-r1
osCommerce oscommerce=2.2ms1j-r2
osCommerce oscommerce=2.2ms1j-r3
osCommerce oscommerce=2.2ms1j-r4
osCommerce oscommerce=2.2ms1j-r5
osCommerce oscommerce=2.2ms1j-r6a
osCommerce oscommerce=2.2ms1j-r7
osCommerce oscommerce=2.2ms1j-r8
Event History
Jan 26, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0311?
CVE-2012-0311 is classified as a medium-severity cross-site scripting vulnerability.
2
How do I fix CVE-2012-0311?
To fix CVE-2012-0311, you should upgrade to osCommerce versions R9 or later that address the XSS vulnerability.
3
What versions of osCommerce are affected by CVE-2012-0311?
CVE-2012-0311 affects osCommerce versions 2.2MS1J prior to R9.
4
What type of attack does CVE-2012-0311 facilitate?
CVE-2012-0311 allows an attacker to inject arbitrary web script or HTML, leading to possible data theft or session hijacking.
5
Is CVE-2012-0311 easy to exploit?
CVE-2012-0311 can be exploited remotely, making it a significant risk if unpatched.