CVE-2012-5315
php iReport 1.0 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in php ireport 1.0 allow remote attackers to inject arbitrary web script or HTML via the message parameter to (1) messages_viewer.php, (2) home.php, or (3) history.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Or4nG.M4N · perlwebappsphp
https://www.exploit-db.com/exploits/18402
Scores
EPSS
0.0033
EPSS Percentile
55.4%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
php_ireport_project/php_ireport
n/a/n/a
Timeline
Published
Oct 08, 2012
Tracked Since
Feb 18, 2026