CVE-2012-5866: XSS
Published Oct 20, 2014
·Updated
Cross-site scripting (XSS) vulnerability in include.php in Achievo 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter.
Affected Software
1 affected component
Achievo Achievo=1.4.5
Event History
Oct 20, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5866?
CVE-2012-5866 is classified as a medium severity vulnerability.
2
How do I fix CVE-2012-5866?
To fix CVE-2012-5866, upgrade Achievo to a newer version that addresses this cross-site scripting vulnerability.
3
What types of attacks can exploit CVE-2012-5866?
CVE-2012-5866 can be exploited to perform cross-site scripting (XSS) attacks, allowing attackers to inject malicious web scripts.
4
Which version of Achievo is affected by CVE-2012-5866?
CVE-2012-5866 affects Achievo version 1.4.5.
5
Is user input vulnerable in CVE-2012-5866?
Yes, user input through the 'field' parameter is vulnerable to arbitrary web script or HTML injection in CVE-2012-5866.