CVE-2012-6644: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to searchresult.php; or (6) type parameter to viewcollection.php or (7) viewitem.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6644?
The severity of CVE-2012-6644 is considered medium due to its ability to allow remote attackers to perform cross-site scripting attacks.
How do I fix CVE-2012-6644?
To fix CVE-2012-6644, update ClipBucket to the latest version where the vulnerabilities are patched.
What versions of ClipBucket are affected by CVE-2012-6644?
CVE-2012-6644 affects ClipBucket version 2.6.
What types of attacks can be executed due to CVE-2012-6644?
CVE-2012-6644 allows attackers to inject arbitrary web scripts or HTML, leading to potential malicious actions such as session hijacking.
Where can the vulnerabilities in CVE-2012-6644 be exploited?
The vulnerabilities in CVE-2012-6644 can be exploited via parameters in channels.php, collections.php, groups.php, videos.php, search_result.php, and the type parameter.