CVE-2012-4768: XSS
Published Sep 4, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
Affected Software
1 affected component
Mikejolley Download Monitor Wordpress=3.3.5.7
Event History
Sep 4, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4768?
CVE-2012-4768 is considered a high severity vulnerability due to the potential for remote attackers to inject malicious scripts.
2
How do I fix CVE-2012-4768?
To fix CVE-2012-4768, update the Download Monitor plugin to version 3.3.5.9 or later.
3
Who is affected by CVE-2012-4768?
CVE-2012-4768 affects users of the Download Monitor plugin versions prior to 3.3.5.9 installed on WordPress.
4
What type of vulnerability is CVE-2012-4768?
CVE-2012-4768 is a cross-site scripting (XSS) vulnerability allowing injection of arbitrary web scripts.
5
What parameters are involved in CVE-2012-4768?
CVE-2012-4768 involves the dlsearch parameter which is manipulated to exploit the vulnerability.