First published: Mon Aug 13 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mysqldumper | =1.24.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4251 is classified as a medium severity vulnerability due to its potential impact on web application security.
To fix CVE-2012-4251, upgrade to MySQLDumper version 1.24.5 or later, where the vulnerabilities have been addressed.
CVE-2012-4251 allows for cross-site scripting (XSS) attacks that enable attackers to inject malicious scripts into web pages.
CVE-2012-4251 affects MySQLDumper version 1.24.4.
CVE-2012-4251 involves vulnerabilities in the page, phase, tablename, dbid, and filename parameters across various scripts.