CVE Database
/

CVE-2012-2156

Back to search

CVE-2012-2156

Published: Apr 11, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the u_email parameter (aka Authors Email field) to manager/users.php, (2) the u_realname parameter (aka Authors Name field) to manager/users.php, or (3) the c_author parameter (aka Author field) in an ADD A COMMENT section.

VendorProductVersions

n/a

n/a

affected
n/a

References

80960
vdb-entry
x_refsource_OSVDB
plumecms-users-xss(74614)
vdb-entry
x_refsource_XF
52890
vdb-entry
x_refsource_BID
18699
exploit
x_refsource_EXPLOIT-DB
80961
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now