CVE-2012-3869: XSS
Published Aug 13, 2012
·Updated
Cross-site scripting (XSS) vulnerability in include/classes/class.rexlist.inc.php in REDAXO 4.3.x and 4.4 allows remote attackers to inject arbitrary web script or HTML via the subpage parameter to index.php.
Affected Software
5 affected components
REDAXO REDAXO=4.3
REDAXO REDAXO=4.3.1
REDAXO REDAXO=4.3.2
REDAXO REDAXO=4.3.3
REDAXO REDAXO=4.4
Event History
Aug 13, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3869?
CVE-2012-3869 is considered a medium-severity vulnerability due to its potential for exploitation through XSS attacks.
2
How do I fix CVE-2012-3869?
To fix CVE-2012-3869, users should upgrade to REDAXO version 4.4.1 or later, where this vulnerability has been addressed.
3
What type of vulnerability is CVE-2012-3869?
CVE-2012-3869 is a cross-site scripting (XSS) vulnerability, allowing remote script injection.
4
Which versions of REDAXO are affected by CVE-2012-3869?
CVE-2012-3869 affects REDAXO versions 4.3.x and 4.4, specifically up to 4.4.0.
5
Can CVE-2012-3869 be exploited remotely?
Yes, CVE-2012-3869 can be exploited remotely by attackers through manipulated subpage parameters.