CVE-2012-4251
Mysqldumper - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
Exploits (4)
References (6)
Scores
EPSS
0.0956
EPSS Percentile
92.8%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
mysqldumper/mysqldumper
n/a/n/a
Timeline
Published
Aug 13, 2012
Tracked Since
Feb 18, 2026