CVE Database
/

CVE-2012-0007

Back to search

CVE-2012-0007

Published: Jan 10, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

51291
vdb-entry
x_refsource_BID
TA12-010A
third-party-advisory
x_refsource_CERT
1026499
vdb-entry
x_refsource_SECTRACK
MS12-007
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:14314
vdb-entry
signature
x_refsource_OVAL
47483
third-party-advisory
x_refsource_SECUNIA
47516
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2012-0007 - Security Vulnerability | QwikSec