First published: Tue Jun 19 2012(Updated: )
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
KENT-WEB WEB PATIO | <=4.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2636 is classified as a cross-site scripting (XSS) vulnerability that can have a high impact on the security of the affected web application.
To fix CVE-2012-2636, you should upgrade KENT-WEB WEB PATIO to version 4.05 or later, which addresses this vulnerability.
CVE-2012-2636 allows remote attackers to inject arbitrary web scripts or HTML, potentially leading to user data theft or session hijacking.
All versions of KENT-WEB WEB PATIO 4.04 and earlier are affected by CVE-2012-2636.
Yes, due to the XSS nature of CVE-2012-2636, it is possible for attackers to compromise user data with malicious scripts.