CVE-2012-2941: XSS
Published May 27, 2012
·Updated
Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTML via the text parameter.
Affected Software
1 affected component
Yandex Yandex.Server 2010=9.0
Event History
May 27, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2941?
CVE-2012-2941 has a medium severity rating due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2012-2941?
To fix CVE-2012-2941, ensure that input validation and sanitization are properly implemented for the text parameter in Yandex.Server 2010 9.0.
3
What systems are affected by CVE-2012-2941?
CVE-2012-2941 specifically affects Yandex.Server 2010 version 9.0 in its Enterprise configuration.
4
What type of vulnerability is CVE-2012-2941?
CVE-2012-2941 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2012-2941 lead to data theft?
Yes, if exploited, CVE-2012-2941 can allow attackers to inject scripts that may lead to data theft or session hijacking.