Sploitus

CVE-2012-0986

No indexed exploits for CVE-2012-0986 yet

Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php.

Affected products
Impresscms
Impresscms
= 1.2, 1.2.1, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.3
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
1.7% (75th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2012-10-06
CVE-2012-0986 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2012-0986 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2012-0986 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.