CVE-2012-4543
published 2013-01-04CVE-2012-4543: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.23%
65.5th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | certificate_system | <= 8.1.1 | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
System: Multiple cross-site scripting flaws by displaying CRL or processing profile
vendor_redhat·2012-12-06·CVSS 4.3
CVE-2012-4543 [MEDIUM] CWE-79 System: Multiple cross-site scripting flaws by displaying CRL or processing profile
System: Multiple cross-site scripting flaws by displaying CRL or processing profile
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script.
GHSA
GHSA-3rg2-g53j-xh7w: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8
ghsa_unreviewed·2022-05-17
CVE-2012-4543 [MEDIUM] CWE-79 GHSA-3rg2-g53j-xh7w: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile [fedora-all]
bugzilla·2012-12-06·CVSS 4.3
CVE-2012-4543 [MEDIUM] CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile [fedora-all]
CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field
Bugzilla
CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile [epel-5]
bugzilla·2012-12-06·CVSS 4.3
CVE-2012-4543 [MEDIUM] CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile [epel-5]
CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes fiel
Bugzilla
CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile
bugzilla·2012-10-09·CVSS 4.3
CVE-2012-4543 [MEDIUM] CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile
CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile
Multiple cross-site scripting (XSS) flaws were found in the way:
1) 'displayCRL' script of Certificate System sanitized content of 'pageStart' and 'pageSize' variables provided in the query string,
2) 'profileProcess' script of Certificate System sanitized content of 'nonce' variable provided in the query string.
A remote attacker could provide a specially-crafted web page that, when visited by an unsuspecting Certificate System user would lead to arbitrary HTML or web script execution in the context of Certificate System user session.
Discussion:
This issue affects the version of the pki-common package, as shipped with Red Hat Certificate System 8.1.
--
This issue affects
http://rhn.redhat.com/errata/RHSA-2012-1550.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0511.htmlhttp://secunia.com/advisories/51482http://www.securityfocus.com/bid/56843http://www.securitytracker.com/id?1027846https://bugzilla.redhat.com/show_bug.cgi?id=864397http://rhn.redhat.com/errata/RHSA-2012-1550.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0511.htmlhttp://secunia.com/advisories/51482http://www.securityfocus.com/bid/56843http://www.securitytracker.com/id?1027846https://bugzilla.redhat.com/show_bug.cgi?id=864397
2013-01-04
Published