VulnerabilityModified
CVE-2012-1217
Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.
MEDIUM 4.3EPSS 1.64%
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- simhl/sths v2 web portal
- Source
- cve@mitre.org
References
- http://0nto.wordpress.com/2012/02/13/sths-v2-web-portal-2-2-sql-injection-vulnerabilty/Exploit
- http://packetstormsecurity.org/files/109665/STHS-v2-Web-Portal-2.2-SQL-Injection.htmlExploit
- http://www.securityfocus.com/bid/51991Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73154
- http://0nto.wordpress.com/2012/02/13/sths-v2-web-portal-2-2-sql-injection-vulnerabilty/Exploit
- http://packetstormsecurity.org/files/109665/STHS-v2-Web-Portal-2.2-SQL-Injection.htmlExploit
- http://www.securityfocus.com/bid/51991Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73154
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.