CVE-2012-4247: XSS
Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) remoteuser, (2) remotedatabase, (3) remoteuserprefix, (4) remotepassword, or (5) remoteprefix parameter to the import4 page; or the (6) id parameter to the bouncerule page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4247?
CVE-2012-4247 has been assigned a medium severity level due to its potential for causing cross-site scripting attacks.
How do I fix CVE-2012-4247?
To fix CVE-2012-4247, upgrade phpList to version 2.10.19 or later.
What types of vulnerabilities are associated with CVE-2012-4247?
CVE-2012-4247 is associated with multiple cross-site scripting (XSS) vulnerabilities.
Which versions of phpList are affected by CVE-2012-4247?
phpList versions prior to 2.10.19 are affected by CVE-2012-4247.
Can CVE-2012-4247 be exploited remotely?
Yes, CVE-2012-4247 can be exploited remotely through specially crafted requests.