CVE-2012-5650: XSS
Published Mar 18, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite.
Affected Software
7 affected components
Apache CouchDB<=1.0.3
Apache CouchDB=1.0.0
Apache CouchDB=1.0.1
Apache CouchDB=1.0.2
Apache CouchDB=1.1.0
Apache CouchDB=1.1.1
Apache CouchDB=1.2.0
Event History
Mar 18, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·05:02 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-5650?
The severity of CVE-2012-5650 is rated as medium due to the potential for remote code execution through cross-site scripting.
2
How do I fix CVE-2012-5650?
To fix CVE-2012-5650, you should upgrade Apache CouchDB to version 1.0.4, 1.1.2, 1.2.1, or later.
3
What versions of Apache CouchDB are affected by CVE-2012-5650?
CVE-2012-5650 affects Apache CouchDB versions prior to 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1.
4
What type of vulnerability is CVE-2012-5650?
CVE-2012-5650 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2012-5650 be exploited remotely?
Yes, CVE-2012-5650 allows remote attackers to inject arbitrary web scripts or HTML.