CVE-2012-3238: XSS
Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3238?
CVE-2012-3238 is rated as a medium severity vulnerability due to its potential for Cross-site scripting (XSS) attacks.
How do I fix CVE-2012-3238?
To fix CVE-2012-3238, update the Astaro Security Gateway software to version 8.305 or later.
What type of vulnerability is CVE-2012-3238?
CVE-2012-3238 is a Cross-site scripting (XSS) vulnerability in the Backup/Restore component of WebAdmin.
Which software versions are affected by CVE-2012-3238?
CVE-2012-3238 affects Astaro Security Gateway versions prior to 8.305 and several versions of Sophos Unified Threat Management.
Can CVE-2012-3238 be exploited remotely?
Yes, CVE-2012-3238 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.