CVE-2012-2683
published 2012-09-28CVE-2012-2683: Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.08%
79.4th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages."
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_mrg | — | — |
| trevor_mckay | cumin | <= 0.1.5192-4 | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| trevor_mckay | cumin | — | — |
| zendframework | zendframework1 | >= 0 < 1.12.4 | 1.12.4 |
| zendframework | zendopenid | >= 0 < 2.0.2 | 2.0.2 |
| zendframework | zendrest | >= 0 < 2.0.2 | 2.0.2 |
| zendframework | zendservice-amazon | >= 0 < 2.0.3 | 2.0.3 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa5.0MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cumin: multiple XSS flaws
vendor_redhat·2012-09-19·CVSS 4.3
CVE-2012-2683 [MEDIUM] CWE-79 cumin: multiple XSS flaws
cumin: multiple XSS flaws
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages."
Package: cumin (Red Hat Enterprise MRG 1) - Will not fix
GHSA
Several Zend Products Vulnerable to XXE and XEE attacks
ghsa·2022-05-14·CVSS 5.0
CVE-2014-2683 [MEDIUM] CWE-611 Several Zend Products Vulnerable to XXE and XEE attacks
Several Zend Products Vulnerable to XXE and XEE attacks
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-6532.
GHSA
GHSA-rgxg-4v48-cv79: Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0
ghsa_unreviewed·2022-05-13
CVE-2012-2683 [MEDIUM] CWE-79 GHSA-rgxg-4v48-cv79: Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4970 lcgdm: multiple SQL injection vulnerabilities
bugzilla·2013-03-12·CVSS 7.5
CVE-2011-4970 [HIGH] CVE-2011-4970 lcgdm: multiple SQL injection vulnerabilities
CVE-2011-4970 lcgdm: multiple SQL injection vulnerabilities
It was reported [1] that DPM (Disk Pool Manager) suffered from multiple SQL injection vulnerabilities. Versions up to and including 1.8.5 are affected; 1.8.6 contains a fix.
[1] https://wiki.egi.eu/wiki/SVG:Advisory-SVG-2012-2683
Discussion:
Created lcgdm tracking bugs for this issue
Affects: fedora-all [bug 920862]
Affects: epel-all [bug 920863]
---
Fedora 17 already contains 1.8.6, as does EPEL5 and 6.
---
And Fedora 18 currently has 1.8.7, so this is resolved across the board.
Bugzilla
CVE-2012-2680 CVE-2012-2681 CVE-2012-2683 CVE-2012-2684 CVE-2012-2685 CVE-2012-2734 CVE-2012-2735 CVE-2012-3459 cumin various flaws [fedora-all]
bugzilla·2012-09-19·CVSS 5.0
CVE-2012-2680 [MEDIUM] CVE-2012-2680 CVE-2012-2681 CVE-2012-2683 CVE-2012-2684 CVE-2012-2685 CVE-2012-2734 CVE-2012-2735 CVE-2012-3459 cumin various flaws [fedora-all]
CVE-2012-2680 CVE-2012-2681 CVE-2012-2683 CVE-2012-2684 CVE-2012-2685 CVE-2012-2734 CVE-2012-2735 CVE-2012-3459 cumin various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submiss
Bugzilla
CVE-2012-2683 cumin: multiple XSS flaws
bugzilla·2012-06-08·CVSS 4.3
CVE-2012-2683 [MEDIUM] CVE-2012-2683 cumin: multiple XSS flaws
CVE-2012-2683 cumin: multiple XSS flaws
Multiple XSS flaws were reported in Cumin. These flaws could be used by a remote attacker to inject arbitrary web script on a web page displayed by Cumin. This includes an XSS in error message displays due to not filtering the displayed output, and not escaping quotes in source HTML on certain pages.
Discussion:
Created attachment 590472
Call xml_escape() on error page content
---
Acknowledgements:
These issues were discovered by Florian Weimer of the Red Hat Product Security Team.
---
This issue has been addressed in following products:
MRG for RHEL-5 v. 2
Via RHSA-2012:1278 https://rhn.redhat.com/errata/RHSA-2012-1278.html
---
This issue has been addressed in following products:
MRG for RHEL-6 v.2
Via RHSA-2012:1281 https://rhn.redhat
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=830243http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092543.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092562.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1278.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1281.htmlhttp://secunia.com/advisories/50660http://www.securityfocus.com/bid/55618https://exchange.xforce.ibmcloud.com/vulnerabilities/78772http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=830243http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092543.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092562.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1278.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1281.htmlhttp://secunia.com/advisories/50660http://www.securityfocus.com/bid/55618https://exchange.xforce.ibmcloud.com/vulnerabilities/78772
2012-09-28
Published