CVE-2012-4451
MEDIUMZend Framework < 2.0.1 - Cross-Site Scripting in Multiple Components
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.
References (8)
Core 8
Core References
Mailing List, Third Party Advisory x_refsource_misc
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688946#10
Third Party Advisory x_refsource_misc
https://bugs.gentoo.org/show_bug.cgi?id=436210
Mailing List, Patch, Third Party Advisory x_refsource_misc
http://seclists.org/oss-sec/2012/q3/571
Mailing List, Patch, Third Party Advisory x_refsource_misc
http://seclists.org/oss-sec/2012/q3/573
Vendor Advisory x_refsource_misc
http://framework.zend.com/security/advisory/ZF2012-03
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=860738
Patch, Third Party Advisory x_refsource_misc
https://github.com/zendframework/zf2/commit/27131ca9520bdf1d4c774c71459eba32f2b10733
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/55636
Scores
CVSS v3
6.1
EPSS
0.0137
EPSS Percentile
69.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (4)
fedoraproject/fedora
16
fedoraproject/fedora
17
redhat/enterprise_linux
6.0
zend/zend_framework
< 2.0.1
Published
Jan 03, 2020
Tracked Since
Feb 18, 2026