CVE-2012-6149
published 2014-02-14CVE-2012-6149: Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.57%
72.6th percentile
Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
| redhat | satellite_5_managed_db | — | — |
| redhat | spacewalk-java | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hr9j-j2w3-gwf8: Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes
ghsa_unreviewed·2022-05-13
CVE-2012-6149 [LOW] CWE-79 GHSA-hr9j-j2w3-gwf8: Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes
Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call.
Red Hat
(spacewalk-java): XSS in system.addNote XML-RPC call due improper sanitization of note's subject and content
vendor_redhat·2014-02-10·CVSS 3.5
CVE-2012-6149 [LOW] CWE-79 (spacewalk-java): XSS in system.addNote XML-RPC call due improper sanitization of note's subject and content
(spacewalk-java): XSS in system.addNote XML-RPC call due improper sanitization of note's subject and content
Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-0148.htmlhttp://secunia.com/advisories/56952https://bugzilla.redhat.com/show_bug.cgi?id=882000https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ac55c6656bb19b3b13fhttps://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=1d0f4b4a78ea03d9f2d05fbd52236b1f2ab68e85https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0148.htmlhttp://secunia.com/advisories/56952https://bugzilla.redhat.com/show_bug.cgi?id=882000https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ac55c6656bb19b3b13fhttps://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=1d0f4b4a78ea03d9f2d05fbd52236b1f2ab68e85https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.html
2014-02-14
Published