CVE-2012-2995: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-BuildWin321394 allow remote attackers to inject arbitrary web script or HTML via (1) the wrsApprovedURL parameter to addRuleAttrWrsApproveUrl.imss or (2) the src parameter to initUpdSchPage.imss.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2995?
CVE-2012-2995 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-2995?
To fix CVE-2012-2995, users should update Trend Micro InterScan Messaging Security Suite to the latest patched version that addresses this vulnerability.
What types of attacks can CVE-2012-2995 be exploited for?
CVE-2012-2995 can be exploited for cross-site scripting attacks, which may allow attackers to inject malicious scripts into web pages viewed by users.
Which versions of Trend Micro InterScan Messaging Security Suite are affected by CVE-2012-2995?
CVE-2012-2995 affects Trend Micro InterScan Messaging Security Suite version 7.1.
What parameters are involved in the CVE-2012-2995 vulnerability?
The parameters involved in CVE-2012-2995 are 'wrsApprovedURL' and 'src', which allow for the injection of malicious scripts.