CVE-2012-3952: XSS
Published Aug 12, 2012
·Updated
Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the unconfirmed parameter to the user page.
Affected Software
23 affected components
PHPlist PHPList<=2.10.18
PHPlist PHPList=2.6.5
PHPlist PHPList=2.7.1
PHPlist PHPList=2.7.2
PHPlist PHPList=2.8.2
PHPlist PHPList=2.8.7
PHPlist PHPList=2.8.12
PHPlist PHPList=2.10.1
PHPlist PHPList=2.10.2
PHPlist PHPList=2.10.3
PHPlist PHPList=2.10.4
PHPlist PHPList=2.10.5
PHPlist PHPList=2.10.7
PHPlist PHPList=2.10.8
PHPlist PHPList=2.10.9
PHPlist PHPList=2.10.10
PHPlist PHPList=2.10.11
PHPlist PHPList=2.10.12
PHPlist PHPList=2.10.13
PHPlist PHPList=2.10.14
PHPlist PHPList=2.10.15
PHPlist PHPList=2.10.16
PHPlist PHPList=2.10.17
Event History
Aug 12, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3952?
CVE-2012-3952 has a medium severity rating as it allows remote attackers to perform cross-site scripting attacks.
2
How do I fix CVE-2012-3952?
To fix CVE-2012-3952, upgrade phpList to version 2.10.19 or later.
3
Which versions of phpList are affected by CVE-2012-3952?
CVE-2012-3952 affects all versions of phpList prior to 2.10.19, including specific versions like 2.6.5 and 2.10.17.
4
Can CVE-2012-3952 impact user data?
Yes, CVE-2012-3952 can potentially impact user data by allowing attackers to inject malicious scripts that could manipulate user interactions.
5
Is there a workaround for CVE-2012-3952?
There is no specific workaround for CVE-2012-3952 other than upgrading to a patched version of phpList.