CVE-2012-10003

A vulnerability, which was classified as problematic, has been found in ahmyi RivetTracker. This issue affects some unknown processing. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The patch is named f053c5cc2bc44269b0496b5f275e349928a92ef9. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217271.
References
Link Resource
https://github.com/ahmyi/rivettracker/commit/f053c5cc2bc44269b0496b5f275e349928a92ef9 Patch Third Party Advisory
https://github.com/ahmyi/rivettracker/pull/1 Patch Third Party Advisory
https://vuldb.com/?ctiid.217271 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.217271 Permissions Required Third Party Advisory VDB Entry
https://github.com/ahmyi/rivettracker/commit/f053c5cc2bc44269b0496b5f275e349928a92ef9 Patch Third Party Advisory
https://github.com/ahmyi/rivettracker/pull/1 Patch Third Party Advisory
https://vuldb.com/?ctiid.217271 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.217271 Permissions Required Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:rivettracker_project:rivettracker:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:36

Type Values Removed Values Added
References () https://github.com/ahmyi/rivettracker/commit/f053c5cc2bc44269b0496b5f275e349928a92ef9 - Patch, Third Party Advisory () https://github.com/ahmyi/rivettracker/commit/f053c5cc2bc44269b0496b5f275e349928a92ef9 - Patch, Third Party Advisory
References () https://github.com/ahmyi/rivettracker/pull/1 - Patch, Third Party Advisory () https://github.com/ahmyi/rivettracker/pull/1 - Patch, Third Party Advisory
References () https://vuldb.com/?ctiid.217271 - Permissions Required, Third Party Advisory, VDB Entry () https://vuldb.com/?ctiid.217271 - Permissions Required, Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.217271 - Permissions Required, Third Party Advisory, VDB Entry () https://vuldb.com/?id.217271 - Permissions Required, Third Party Advisory, VDB Entry
Summary
  • (es) Se ha encontrado una vulnerabilidad en ahmyi RivetTracker y se ha clasificado como problemática. Este problema afecta algún procesamiento desconocido. La manipulación del argumento $_SERVER['PHP_SELF'] conduce a cross-site scripting. El ataque puede iniciarse de forma remota. El parche se llama f053c5cc2bc44269b0496b5f275e349928a92ef9. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-217271.
CVSS v2 : 4.0
v3 : 6.1
v2 : 4.0
v3 : 3.5

29 Feb 2024, 01:12

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-03 12:15

Updated : 2024-11-21 01:36


NVD link : CVE-2012-10003

Mitre link : CVE-2012-10003

CVE.ORG link : CVE-2012-10003


JSON object : View

Products Affected

rivettracker_project

  • rivettracker
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')