First published: Tue Feb 14 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the Yet another Google search (ya_googlesearch) extension before 0.3.10 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Search | <=0.3.9 | |
Google Search | =0.3.4 | |
Google Search | =0.3.5 | |
Google Search | =0.3.6 | |
Google Search | =0.3.7 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1081 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
To fix CVE-2012-1081, upgrade the ya_googlesearch extension to version 0.3.10 or later.
CVE-2012-1081 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
CVE-2012-1081 affects ya_googlesearch versions up to and including 0.3.9.
The vendor of the affected software for CVE-2012-1081 is Roderick Braun.