CVE-2012-2536
Microsoft System Center Configuration Manager 2007 SP2 - Reflected Cross-Site Scripting
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15781
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA12-255A.html
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-062
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/55430
Scores
EPSS
0.1616
EPSS Percentile
96.6%
Details
CWE
CWE-79
Status
published
Products (2)
microsoft/system_center_configuration_manager
2007 sp2
microsoft/systems_management_server
2003 sp2
Published
Sep 11, 2012
Tracked Since
Feb 18, 2026