CVE-2012-4246
Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter; or the (2) footer, (3) status, or (4) testtarget parameter in the send page.
- Affected products
- Phplist
- Phplist
- ≤ 2.10.18, 2.6.5, 2.7.1, 2.7.2, 2.8.2, 2.8.7, 2.8.12, 2.10.1, 2.10.2, 2.10.3, 2.10.4, 2.10.5, 2.10.7, 2.10.8, 2.10.9, 2.10.10, 2.10.11, 2.10.12, 2.10.13, 2.10.14, 2.10.15, 2.10.16, 2.10.17
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.9% (77th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2012-08-12
CVE-2012-4246 at NVD
1 known exploit for CVE-2012-4246
Proof-of-concept code and exploit modules indexed by Sploitus