Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16 and earlier for iOS on the iPad, and 3.15.1 and earlier for iOS on the iPhone and iPod touch, allows remote attackers to inject arbitrary web script or HTML via vectors involving use of this app in conjunction with a web browser.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
21 Nov 2024, 01:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://jvn.jp/en/jp/JVN01598734/index.html - | |
References | () http://jvndb.jvn.jp/jvndb/JVNDB-2012-000073 - |
Information
Published : 2012-08-07 19:55
Updated : 2024-11-21 01:39
NVD link : CVE-2012-2648
Mitre link : CVE-2012-2648
CVE.ORG link : CVE-2012-2648
JSON object : View
Products Affected
apple
- ipad
- iphone_os
- ipod_touch
goodiware
- goodreader
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')