CVE-2012-10002

A vulnerability was found in ahmyi RivetTracker. It has been declared as problematic. Affected by this vulnerability is the function changeColor of the file css.php. The manipulation of the argument set_css leads to cross site scripting. The attack can be launched remotely. The patch is named 45a0f33876d58cb7e4a0f17da149e58fc893b858. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217267.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rivettracker_project:rivettracker:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:36

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en ahmyi RivetTracker. Ha sido declarada problemática. La función changeColor del archivo css.php es afectada por esta vulnerabilidad. La manipulación del argumento set_css conduce a cross-site scripting. El ataque se puede lanzar de forma remota. El parche se llama 45a0f33876d58cb7e4a0f17da149e58fc893b858. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-217267.
CVSS v2 : 4.0
v3 : 6.1
v2 : 4.0
v3 : 3.5
References () https://github.com/ahmyi/rivettracker/commit/45a0f33876d58cb7e4a0f17da149e58fc893b858 - Patch, Third Party Advisory () https://github.com/ahmyi/rivettracker/commit/45a0f33876d58cb7e4a0f17da149e58fc893b858 - Patch, Third Party Advisory
References () https://github.com/ahmyi/rivettracker/pull/1 - Patch, Third Party Advisory () https://github.com/ahmyi/rivettracker/pull/1 - Patch, Third Party Advisory
References () https://vuldb.com/?ctiid.217267 - Third Party Advisory () https://vuldb.com/?ctiid.217267 - Third Party Advisory
References () https://vuldb.com/?id.217267 - Third Party Advisory () https://vuldb.com/?id.217267 - Third Party Advisory

29 Feb 2024, 01:12

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-03 09:15

Updated : 2024-11-21 01:36


NVD link : CVE-2012-10002

Mitre link : CVE-2012-10002

CVE.ORG link : CVE-2012-10002


JSON object : View

Products Affected

rivettracker_project

  • rivettracker
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')