CVE-2012-4246: XSS
Published Aug 12, 2012
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter; or the (2) footer, (3) status, or (4) testtarget parameter in the send page.
Affected Software
23 affected components
PHPlist PHPList<=2.10.18
PHPlist PHPList=2.6.5
PHPlist PHPList=2.7.1
PHPlist PHPList=2.7.2
PHPlist PHPList=2.8.2
PHPlist PHPList=2.8.7
PHPlist PHPList=2.8.12
PHPlist PHPList=2.10.1
PHPlist PHPList=2.10.2
PHPlist PHPList=2.10.3
PHPlist PHPList=2.10.4
PHPlist PHPList=2.10.5
PHPlist PHPList=2.10.7
PHPlist PHPList=2.10.8
PHPlist PHPList=2.10.9
PHPlist PHPList=2.10.10
PHPlist PHPList=2.10.11
PHPlist PHPList=2.10.12
PHPlist PHPList=2.10.13
PHPlist PHPList=2.10.14
PHPlist PHPList=2.10.15
PHPlist PHPList=2.10.16
PHPlist PHPList=2.10.17
Remediation
Patch Available
Event History
Aug 12, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4246?
CVE-2012-4246 has a high severity rating due to its potential for remote script injection and exploitation.
2
How do I fix CVE-2012-4246?
To fix CVE-2012-4246, upgrade phpList to version 2.10.19 or later.
3
What versions are affected by CVE-2012-4246?
CVE-2012-4246 affects phpList versions prior to 2.10.19, including all versions from 2.6.5 up to 2.10.18.
4
What types of vulnerabilities are described in CVE-2012-4246?
CVE-2012-4246 describes multiple cross-site scripting (XSS) vulnerabilities.
5
Can CVE-2012-4246 allow attackers to compromise my system?
Yes, CVE-2012-4246 can allow attackers to inject arbitrary web scripts, potentially compromising the system.