CVE-2012-0428 — Cross-site Scripting in Edirectory

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 51.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 25
Latest updateMay 4

Description

Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

â–¶NVDmicrofocus/edirectory9 versions+8

🔴Vulnerability Details

2
GHSA
GHSA-8gqm-59h7-gqvf: Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8↗2022-05-04
â–¶
CVEList
CVE-2012-0428: Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8↗2012-12-25
â–¶

💥Exploits & PoCs

2
Exploit-DB
LANDesk Lenovo ThinkManagement Suite 9.0.3 Core Server - Arbitrary File Deletion↗2012-03-19
â–¶
Exploit-DB
LANDesk Lenovo ThinkManagement Suite 9.0.3 - Core Server Remote Code Execution↗2012-03-19
â–¶

📋Vendor Advisories

1
Red Hat
OpenJDK: reflection API incorrect checks for proxy classes (Libraries, 7197546, SE-2012-01 Issue 29)↗2013-02-01
â–¶
CVE-2012-0428 — Cross-site Scripting in Edirectory | cvebase