CVE-2012-4923
Endian Firewall 2.4 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.
Exploits (3)
exploitdb
WRITEUP
VERIFIED
by Vulnerability Research Laboratory · textremotehardware
https://www.exploit-db.com/exploits/36833
exploitdb
WRITEUP
VERIFIED
by Vulnerability Research Laboratory · textremotehardware
https://www.exploit-db.com/exploits/36832
exploitdb
WRITEUP
VERIFIED
by Vulnerability Research Laboratory · textremotehardware
https://www.exploit-db.com/exploits/36831
References (4)
Scores
EPSS
0.0319
EPSS Percentile
86.9%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
endian/firewall
n/a/n/a
Timeline
Published
Sep 15, 2012
Tracked Since
Feb 18, 2026