CVE-2012-2662
published 2012-08-13CVE-2012-2662: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.37%
68.9th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | certificate_system | <= 8.1 | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4x57-6h7g-39hp: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8
ghsa_unreviewed·2022-05-17
CVE-2012-2662 [MEDIUM] CWE-79 GHSA-4x57-6h7g-39hp: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages.
Red Hat
System: multiple XSS flaws
vendor_redhat·2012-07-19·CVSS 4.3
CVE-2012-2662 [MEDIUM] CWE-79 System: multiple XSS flaws
System: multiple XSS flaws
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages.
Multiple cross-site scripting flaws were discovered in the Red Hat Certificate System Agent and End Entity pages. An attacker could use these flaws to perform a cross-site scripting (XSS) attack against victims using the Certificate System's web interface.
Package: pki-core (Red Hat Enterprise Linux 7) - Will not fix
No detection rules found.
No public exploits indexed.
http://osvdb.org/84099http://rhn.redhat.com/errata/RHSA-2012-1103.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1347.htmlhttp://secunia.com/advisories/50013http://www.securityfocus.com/bid/54608http://www.securitytracker.com/id?1027284https://exchange.xforce.ibmcloud.com/vulnerabilities/77101http://osvdb.org/84099http://rhn.redhat.com/errata/RHSA-2012-1103.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1347.htmlhttp://secunia.com/advisories/50013http://www.securityfocus.com/bid/54608http://www.securitytracker.com/id?1027284https://exchange.xforce.ibmcloud.com/vulnerabilities/77101
2012-08-13
Published