CVE-2012-0312: XSS
Published Jan 26, 2012
·Updated
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
10 affected components
osCommerce Online Merchant<=2.3.0
osCommerce Online Merchant=2.2
osCommerce oscommerce=2.2ms1j-r1
osCommerce oscommerce=2.2ms1j-r2
osCommerce oscommerce=2.2ms1j-r3
osCommerce oscommerce=2.2ms1j-r4
osCommerce oscommerce=2.2ms1j-r5
osCommerce oscommerce=2.2ms1j-r6a
osCommerce oscommerce=2.2ms1j-r7
osCommerce oscommerce=2.2ms1j-r8
Event History
Jan 26, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0312?
CVE-2012-0312 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2012-0312?
To fix CVE-2012-0312, upgrade to osCommerce 2.3.1 or later.
3
Which versions are affected by CVE-2012-0312?
CVE-2012-0312 affects osCommerce 2.2 before R9 and osCommerce Online Merchant before 2.3.1.
4
What type of vulnerability is CVE-2012-0312?
CVE-2012-0312 is a cross-site scripting (XSS) vulnerability.
5
Can remote attackers exploit CVE-2012-0312?
Yes, remote attackers can exploit CVE-2012-0312 to inject arbitrary web scripts or HTML.