First published: Tue Sep 25 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the management screen in myLittleTools myLittleAdmin for SQL Server 2000 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted database entry.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
myLittleAdmin | =1.2.a | |
myLittleAdmin | =1.2.b | |
myLittleAdmin | =1.5.a | |
myLittleAdmin | =2.0 | |
myLittleAdmin | =2.5 | |
myLittleAdmin | =2.7 | |
Microsoft SQL Server | =2000 | |
Microsoft SQL Server | =2000-gold | |
Microsoft SQL Server | =2000-sp1 | |
Microsoft SQL Server | =2000-sp2 | |
Microsoft SQL Server | =2000-sp3 | |
Microsoft SQL Server | =2000-sp3a | |
Microsoft SQL Server | =2000-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4015 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2012-4015, update myLittleAdmin to a version that has patched the XSS vulnerability.
Versions 1.2.a, 1.2.b, 1.5.a, 2.0, 2.5, and 2.7 of myLittleAdmin are affected by CVE-2012-4015.
CVE-2012-4015 can facilitate remote attacks that inject arbitrary web scripts or HTML into the management screen.
CVE-2012-4015 occurs specifically in the management screen of myLittleAdmin for SQL Server 2000.