CVE-2012-1301: Input Validation
Published Apr 13, 2017
·Updated
The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.
Affected Software
1 affected component
Umbraco Umbraco CMS=4.7.0
Event History
Apr 13, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1301?
CVE-2012-1301 has a moderate severity rating due to its ability to allow remote attackers to proxy requests.
2
How do I fix CVE-2012-1301?
To fix CVE-2012-1301, it is recommended to upgrade Umbraco CMS to a version higher than 4.7.0.
3
What software is affected by CVE-2012-1301?
CVE-2012-1301 specifically affects Umbraco CMS version 4.7.0.
4
What does CVE-2012-1301 exploit?
CVE-2012-1301 exploits the FeedProxy.aspx script by manipulating the "url" parameter to proxy requests.
5
Can CVE-2012-1301 lead to further attacks?
Yes, CVE-2012-1301 can lead to further attacks such as SSRF (Server-Side Request Forgery) due to its proxying capability.