First published: Fri Sep 28 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trevor McKay Cumin | <=0.1.5192-4 | |
Trevor McKay Cumin | =0.1.3160-1 | |
Trevor McKay Cumin | =0.1.4369-1 | |
Trevor McKay Cumin | =0.1.4410-2 | |
Trevor McKay Cumin | =0.1.4494-1 | |
Trevor McKay Cumin | =0.1.4794-1 | |
Trevor McKay Cumin | =0.1.4916-1 | |
Trevor McKay Cumin | =0.1.5033-1 | |
Trevor McKay Cumin | =0.1.5037-1 | |
Trevor McKay Cumin | =0.1.5054-1 | |
Trevor McKay Cumin | =0.1.5068-1 | |
Trevor McKay Cumin | =0.1.5092-1 | |
Trevor McKay Cumin | =0.1.5098-2 | |
Trevor McKay Cumin | =0.1.5105-1 | |
Trevor McKay Cumin | =0.1.5137-1 | |
Trevor McKay Cumin | =0.1.5137-2 | |
Trevor McKay Cumin | =0.1.5137-3 | |
Trevor McKay Cumin | =0.1.5137-4 | |
Trevor McKay Cumin | =0.1.5137-5 | |
Trevor McKay Cumin | =0.1.5192-1 | |
Red Hat Enterprise MRG | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2683 has a moderate severity level due to its multiple cross-site scripting (XSS) vulnerabilities.
To fix CVE-2012-2683, update Cumin to version 0.1.5444 or later.
CVE-2012-2683 affects multiple versions of Trevor McKay's Cumin prior to 0.1.5444 and Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0.
CVE-2012-2683 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2012-2683 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.