CVE-2012-3844: XSS
Published Jul 3, 2012
·Updated
Cross-site scripting (XSS) vulnerability in vBulletin 4.1.12 allows remote attackers to inject arbitrary web script or HTML via a long string in the subject parameter when creating a post.
Affected Software
1 affected component
vBulletin vBulletin=4.1.12
Event History
Jul 3, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3844?
The severity of CVE-2012-3844 is deemed to be high due to the potential for remote attackers to execute arbitrary scripts.
2
How do I fix CVE-2012-3844?
To fix CVE-2012-3844, upgrade vBulletin to a version that is not vulnerable, specifically any version after 4.1.12.
3
What systems are affected by CVE-2012-3844?
CVE-2012-3844 affects vBulletin version 4.1.12.
4
What type of vulnerability is CVE-2012-3844?
CVE-2012-3844 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2012-3844 be exploited through user input?
Yes, CVE-2012-3844 can be exploited by injecting scripts through a long string in the subject parameter when creating a post.