CVE Database
/

CVE-2012-4776

Back to search

CVE-2012-4776

Published: Nov 14, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

TA12-318A
third-party-advisory
x_refsource_CERT
MS12-074
vendor-advisory
x_refsource_MS
56463
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:15810
vdb-entry
signature
x_refsource_OVAL
87266
vdb-entry
x_refsource_OSVDB
51236
third-party-advisory
x_refsource_SECUNIA
1027753
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now