CVE-2012-0974
OSClass <2.3.5 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and (4) sPriceMin parameters in a search action to index.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/36626
Scores
EPSS
0.1138
EPSS Percentile
93.5%
Classification
CWE
CWE-79
Status
published
Affected Products (22)
juan_ramon/osclass
< 2.3.4
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
juan_ramon/osclass
... and 7 more
Timeline
Published
Sep 25, 2012
Tracked Since
Feb 18, 2026