CVE-2012-4247

phplist < 2.10.19 - Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4247.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability to add an admin account and an XSS vulnerability in phplist 2.10.9. The CSRF form submits crafted parameters to create a privileged user, while the XSS form injects arbitrary script via the 'testtarget' parameter.

Description

Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) remote_user, (2) remote_database, (3) remote_userprefix, (4) remote_password, or (5) remote_prefix parameter to the import4 page; or the (6) id parameter to the bouncerule page.

Exploits (1)

exploitdb WORKING POC
htmlwebappsphp
https://www.exploit-db.com/exploits/18419

This exploit demonstrates a CSRF vulnerability to add an admin account and an XSS vulnerability in phplist 2.10.9. The CSRF form submits crafted parameters to create a privileged user, while the XSS form injects arbitrary script via the 'testtarget' parameter.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: phplist version 2.10.9
No auth needed
Prerequisites: Victim must visit a malicious page hosting the exploit forms · Target application must be phplist 2.10.9
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Patch x_refsource_confirm
http://www.phplist.com/?lid=579
Various Sources x_refsource_misc
https://www.httpcs.com/advisories
Vendor Advisory x_refsource_misc
https://www.httpcs.com/advisory/httpcs1
Vendor Advisory x_refsource_misc
https://www.httpcs.com/advisory/httpcs4
Vendor Advisory x_refsource_misc
https://www.httpcs.com/advisory/httpcs3
Vendor Advisory x_refsource_misc
https://www.httpcs.com/advisory/httpcs2
Vendor Advisory x_refsource_misc
https://www.httpcs.com/advisory/httpcs6
Vendor Advisory x_refsource_misc
https://www.httpcs.com/advisory/httpcs7

Scores

EPSS 0.0511
EPSS Percentile 90.1%

Details

CWE
CWE-79
Status published
Products (23)
phplist/phplist 2.6.5
phplist/phplist 2.7.1
phplist/phplist 2.7.2
phplist/phplist 2.8.2
phplist/phplist 2.8.7
phplist/phplist 2.8.12
phplist/phplist 2.10.1
phplist/phplist 2.10.2
phplist/phplist 2.10.3
phplist/phplist 2.10.4
... and 13 more
Published Aug 12, 2012
Tracked Since Feb 18, 2026