cbcvebase.
CVE-2012-2683
published 2012-09-28

CVE-2012-2683: Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow…

PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.08%
79.4th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages."

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
redhatenterprise_mrg
trevor_mckaycumin<= 0.1.5192-4
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
trevor_mckaycumin
zendframeworkzendframework1>= 0 < 1.12.41.12.4
zendframeworkzendopenid>= 0 < 2.0.22.0.2
zendframeworkzendrest>= 0 < 2.0.22.0.2
zendframeworkzendservice-amazon>= 0 < 2.0.32.0.3

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa5.0MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.