CVE-2012-1597

Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ez:ezjscore:*:*:*:*:*:*:*:*
cpe:2.3:a:ez:ezjscore:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:37

Type Values Removed Values Added
References () http://share.ez.no/community-project/security-advisories/ezsa-2012-006-xss-exploit-on-ezjscore-run-command-when-using-firefox - () http://share.ez.no/community-project/security-advisories/ezsa-2012-006-xss-exploit-on-ezjscore-run-command-when-using-firefox -
References () http://www.openwall.com/lists/oss-security/2012/05/11/6 - () http://www.openwall.com/lists/oss-security/2012/05/11/6 -
References () https://github.com/ezsystems/ezjscore/commit/58854564c7b8672090c25c4b1677d08620d870f2 - Exploit, Patch () https://github.com/ezsystems/ezjscore/commit/58854564c7b8672090c25c4b1677d08620d870f2 - Exploit, Patch

Information

Published : 2012-08-17 00:55

Updated : 2024-11-21 01:37


NVD link : CVE-2012-1597

Mitre link : CVE-2012-1597

CVE.ORG link : CVE-2012-1597


JSON object : View

Products Affected

ez

  • ezjscore
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')