Sploitus

CVE-2012-4246

1 known exploit for CVE-2012-4246

Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter; or the (2) footer, (3) status, or (4) testtarget parameter in the send page.

Affected products
Phplist
Phplist
≤ 2.10.18, 2.6.5, 2.7.1, 2.7.2, 2.8.2, 2.8.7, 2.8.12, 2.10.1, 2.10.2, 2.10.3, 2.10.4, 2.10.5, 2.10.7, 2.10.8, 2.10.9, 2.10.10, 2.10.11, 2.10.12, 2.10.13, 2.10.14, 2.10.15, 2.10.16, 2.10.17
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
1.9% (77th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2012-08-12
CVE-2012-4246 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2012-4246

Proof-of-concept code and exploit modules indexed by Sploitus