CVE-2012-1575
published 2012-04-22CVE-2012-1575: Multiple cross-site scripting (XSS) vulnerabilities in Cumin before r5238 allow remote attackers to inject arbitrary web script or HTML via vectors involving…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.38%
82.0th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before r5238 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) widgets or (2) pages.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| trevor_mckay | cumin | <= r5237 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cumin: multiple XSS flaws
vendor_redhat·2012-03-06·CVSS 4.3
CVE-2012-1575 [MEDIUM] CWE-79 cumin: multiple XSS flaws
cumin: multiple XSS flaws
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before r5238 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) widgets or (2) pages.
Package: cumin (Red Hat Enterprise MRG 1) - Will not fix
GHSA
GHSA-v47v-hq34-79pq: Multiple cross-site scripting (XSS) vulnerabilities in Cumin before r5238 allow remote attackers to inject arbitrary web script or HTML via vectors in
ghsa_unreviewed·2022-05-14
CVE-2012-1575 [MEDIUM] CWE-79 GHSA-v47v-hq34-79pq: Multiple cross-site scripting (XSS) vulnerabilities in Cumin before r5238 allow remote attackers to inject arbitrary web script or HTML via vectors in
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before r5238 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) widgets or (2) pages.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1575 cumin: multiple XSS flaws [fedora-all]
bugzilla·2012-04-12·CVSS 4.3
CVE-2012-1575 [MEDIUM] CVE-2012-1575 cumin: multiple XSS flaws [fedora-all]
CVE-2012-1575 cumin: multiple XSS flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=805712
Please no
Bugzilla
CVE-2012-1575 cumin: multiple XSS flaws
bugzilla·2012-03-21·CVSS 4.3
CVE-2012-1575 [MEDIUM] CVE-2012-1575 cumin: multiple XSS flaws
CVE-2012-1575 cumin: multiple XSS flaws
A number of XSS flaws were reported in Cumin. These flaws could be used by a remote attacker to inject arbitrary web script on a web page displayed by Cumin.
To solve the problem, xml_escape() (as defined in wooly/python/wooly/util.py, a simple wrapper around xml.sax.saxutils.escape()) is called on any values that are displayed on a web page and originate outside of Cumin, or through a form submitted by a user. Many of these have been corrected upstream in r5238 [1].
[1] https://fedorahosted.org/pipermail/cumin-developers/2012-March/000796.html
Discussion:
Created attachment 571986
Technical write up on vulnerabilities, fixes, and testing
Slightly different than the original version, but only because I changed the integers used in alert scripts
http://rhn.redhat.com/errata/RHSA-2012-0476.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0477.htmlhttp://secunia.com/advisories/48810http://secunia.com/advisories/48829http://www.securityfocus.com/bid/53000http://www.securitytracker.com/id?1026921https://bugzilla.redhat.com/attachment.cgi?id=571986https://bugzilla.redhat.com/show_bug.cgi?id=805712https://exchange.xforce.ibmcloud.com/vulnerabilities/74844https://fedorahosted.org/pipermail/cumin-developers/2012-March/000796.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0476.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0477.htmlhttp://secunia.com/advisories/48810http://secunia.com/advisories/48829http://www.securityfocus.com/bid/53000http://www.securitytracker.com/id?1026921https://bugzilla.redhat.com/attachment.cgi?id=571986https://bugzilla.redhat.com/show_bug.cgi?id=805712https://exchange.xforce.ibmcloud.com/vulnerabilities/74844https://fedorahosted.org/pipermail/cumin-developers/2012-March/000796.html
2012-04-22
Published