First published: Fri Jun 13 2014(Updated: )
Cross-site scripting (XSS) vulnerability in contrib/langwiz.php in GeSHi before 1.0.8.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Geshi | <=1.0.8.10 | |
Geshi | =1.0.8.4 | |
Geshi | =1.0.8.5 | |
Geshi | =1.0.8.6 | |
Geshi | =1.0.8.7 | |
Geshi | =1.0.8.8 | |
Geshi | =1.0.8.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3522 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2012-3522, upgrade GeSHi to version 1.0.8.11 or later.
CVE-2012-3522 allows remote attackers to perform cross-site scripting (XSS) attacks, injecting arbitrary web scripts or HTML.
CVE-2012-3522 affects GeSHi versions before 1.0.8.11, including versions 1.0.8.4 to 1.0.8.10.
The vulnerable component in CVE-2012-3522 is contrib/langwiz.php in the GeSHi library.