CVE-2012-2563

Multiple cross-site scripting (XSS) vulnerabilities in Bloxx Web Filtering before 5.0.14 allow (1) remote attackers to inject arbitrary web script or HTML via web traffic that is examined within the Bloxx Reports component, and allow (2) remote authenticated administrators to inject arbitrary web script or HTML via vectors involving administrative menu functions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bloxx:web_filtering:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:39

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/722963 - US Government Resource () http://www.kb.cert.org/vuls/id/722963 - US Government Resource
References () http://www.kb.cert.org/vuls/id/MAPG-8R9LBY - () http://www.kb.cert.org/vuls/id/MAPG-8R9LBY -
References () http://www.securityfocus.com/bid/53715 - () http://www.securityfocus.com/bid/53715 -

Information

Published : 2012-06-09 00:55

Updated : 2024-11-21 01:39


NVD link : CVE-2012-2563

Mitre link : CVE-2012-2563

CVE.ORG link : CVE-2012-2563


JSON object : View

Products Affected

bloxx

  • web_filtering
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')