cbcvebase.
CVE-2012-0040
published 2012-01-24

CVE-2012-0040: Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote…

medium4.3CVSS 3.1
AVNACMAuNCNIPAN
Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiansimplesamlphp< simplesamlphp 1.8.2-1 (bookworm)simplesamlphp 1.8.2-1 (bookworm)
simplesamlphpsimplesamlphp<= 1.8.1
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp>= 0 < 1.8.2-11.8.2-1
simplesamlphpsimplesamlphp>= 0 < 1.8.2-11.8.2-1

CVSS provenance

nvd4.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM