CVE-2012-1825: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a forgotpass action or (2) the username parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1825?
CVE-2012-1825 is rated as medium severity due to the potential for cross-site scripting attacks.
What systems are affected by CVE-2012-1825?
CVE-2012-1825 affects ForeScout CounterACT versions 6.3.3.2 through 6.3.4.10.
How do I fix CVE-2012-1825?
To fix CVE-2012-1825, it is recommended to upgrade to a version of ForeScout CounterACT that is not affected.
What types of attacks can CVE-2012-1825 facilitate?
CVE-2012-1825 can allow remote attackers to execute arbitrary web scripts or HTML via specific parameters.
Is CVE-2012-1825 a documented vulnerability?
Yes, CVE-2012-1825 is documented and has been listed in official vulnerability databases.