CVE-2012-4043
Cross-site scripting (XSS) vulnerability in global-protect/login.esp in Palo Alto Networks Global Protect Portal, Global Protect Gateway, and SSL VPN portals 3.1.x through 3.1.11 and 4.0.x through 4.0.5 allows remote attackers to inject arbitrary web script or HTML via the inputStr parameter in a Login action.
- Affected products
- Globalprotect Gateway, Globalprotect Portal, Ssl Vpn
- Palo Alto Global Protected Gateway
- = 3.1, 3.1.11, 4.0, 4.0.5
- Palo Alto Ssl Vpn
- = 3.1, 3.1.11, 4.0, 4.0.5
- Palo Alto Networks
- = global_protect_portal
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.4% (70th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2012-07-26
CVE-2012-4043 at NVD
No indexed exploits for CVE-2012-4043 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2012-4043 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.