First published: Sat Sep 15 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Mod Pagespeed | =0.10.19.1 | |
Google Mod Pagespeed | =0.10.22.4 | |
Apache HTTP Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-4360 is classified as a high risk due to the potential for remote attackers to exploit the XSS vulnerability.
To fix CVE-2012-4360, upgrade to mod_pagespeed version 0.10.22.6 or later, or disable the mod_pagespeed module entirely.
CVE-2012-4360 affects mod_pagespeed versions 0.10.19.1 through 0.10.22.4.
CVE-2012-4360 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
No, the Apache HTTP Server is not directly affected by CVE-2012-4360; only the mod_pagespeed module versions specified are vulnerable.