CVE-2012-4015: XSS
Published Sep 25, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the management screen in myLittleTools myLittleAdmin for SQL Server 2000 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted database entry.
Affected Software
13 affected components
myLittleTools myLittleAdmin=1.2.a
myLittleTools myLittleAdmin=1.2.b
myLittleTools myLittleAdmin=1.5.a
myLittleTools myLittleAdmin=2.0
myLittleTools myLittleAdmin=2.5
myLittleTools myLittleAdmin=2.7
Microsoft SQL Server=2000
Microsoft SQL Server=2000-gold
Microsoft SQL Server=2000-sp1
Microsoft SQL Server=2000-sp2
Microsoft SQL Server=2000-sp3
Microsoft SQL Server=2000-sp3a
Microsoft SQL Server=2000-sp4
Event History
Sep 25, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4015?
CVE-2012-4015 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2012-4015?
To fix CVE-2012-4015, update myLittleAdmin to a version that has patched the XSS vulnerability.
3
Which versions of myLittleAdmin are affected by CVE-2012-4015?
Versions 1.2.a, 1.2.b, 1.5.a, 2.0, 2.5, and 2.7 of myLittleAdmin are affected by CVE-2012-4015.
4
What types of attacks can CVE-2012-4015 facilitate?
CVE-2012-4015 can facilitate remote attacks that inject arbitrary web scripts or HTML into the management screen.
5
Where in the myLittleAdmin application does CVE-2012-4015 occur?
CVE-2012-4015 occurs specifically in the management screen of myLittleAdmin for SQL Server 2000.