CVE-2012-3551: XSS
Published Sep 5, 2012
·Updated
Cross-site scripting (XSS) vulnerability in crowbarframework/app/views/support/index.html.haml in the Crowbar barclamp in Crowbar, possibly 1.4 and earlier, allows remote attackers to inject arbitrary web script or HTML via the file parameter to /utils.
Affected Software
1 affected component
Dell Crowbar<=1.4
Remediation
Event History
Sep 5, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3551?
CVE-2012-3551 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2012-3551?
To fix CVE-2012-3551, upgrade to a version of Crowbar later than 1.4 that addresses the XSS vulnerability.
3
What type of attack does CVE-2012-3551 allow?
CVE-2012-3551 allows remote attackers to inject arbitrary web scripts or HTML into the application.
4
Which versions of Crowbar are affected by CVE-2012-3551?
CVE-2012-3551 affects Crowbar versions 1.4 and earlier.
5
Where is the vulnerability located in Crowbar related to CVE-2012-3551?
The vulnerability related to CVE-2012-3551 is located in the crowbar_framework/app/views/support/index.html.haml file.