cbcvebase.
CVE-2012-6684
published 2015-01-08

CVE-2012-6684: Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via…

PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.25%
81.2th percentile
Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.

Affected

4 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianruby-redcloth< ruby-redcloth 4.2.9-4 (bookworm)ruby-redcloth 4.2.9-4 (bookworm)
redclothredcloth_library<= 4.2.9
redclothredcloth_library>= 0 < 4.3.04.3.0

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.