Back to search
CVE-2012-2112
Published: Aug 27, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6.x before 4.6.8, and 4.7 allows remote attackers to inject arbitrary web script or HTML via exception messages.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[TYPO3-announce] 20120417 Cross-Site Scripting Vulnerability in TYPO3 Core
mailing-list
x_refsource_MLIST
exceptionhandler-exceptionmessages-xss(74920)
vdb-entry
x_refsource_XF
53047
vdb-entry
x_refsource_BID
[TYPO3-announce] 20120417 Announcing TYPO3 4.4.15, 4.5.15 and 4.6.8
mailing-list
x_refsource_MLIST
[oss-security] 20120417 CVE-request: TYPO3-CORE-SA-2012-002 XSS in TYPO3 Core
mailing-list
x_refsource_MLIST
[oss-security] 20120417 Re: CVE-request: TYPO3-CORE-SA-2012-002 XSS in TYPO3 Core
mailing-list
x_refsource_MLIST
DSA-2455
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now