First published: Sat Jul 07 2012(Updated: )
Cross-site scripting (XSS) vulnerability in KENT-WEB YY-BOARD before 6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted form entry.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
KENT-WEB YY-BOARD | <=6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2643 is classified as a medium severity vulnerability due to its potential impact on user data.
To resolve CVE-2012-2643, upgrade KENT-WEB YY-BOARD to version 6.4 or later.
CVE-2012-2643 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Users of KENT-WEB YY-BOARD prior to version 6.4 are affected by CVE-2012-2643.
Yes, CVE-2012-2643 can be exploited remotely by attackers through crafted form entries.