CVE-2012-0908

EUVD-2012-0931
Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
simplesamlphpsimplesamlphp
𝑥
≤ 1.8.1
simplesamlphpsimplesamlphp
0.4
simplesamlphpsimplesamlphp
0.5
simplesamlphpsimplesamlphp
1.0
simplesamlphpsimplesamlphp
1.1
simplesamlphpsimplesamlphp
1.2
simplesamlphpsimplesamlphp
1.3
simplesamlphpsimplesamlphp
1.4
simplesamlphpsimplesamlphp
1.5
simplesamlphpsimplesamlphp
1.5.1
simplesamlphpsimplesamlphp
1.6
simplesamlphpsimplesamlphp
1.6.1
simplesamlphpsimplesamlphp
1.6.2
simplesamlphpsimplesamlphp
1.6.3
simplesamlphpsimplesamlphp
1.7
simplesamlphpsimplesamlphp
1.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
simplesamlphp
bookworm
1.19.7-1
fixed
bullseye
1.19.0-1
fixed
sid
1.19.7-1
fixed
trixie
1.19.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
simplesamlphp
hardy
dne
lucid
dne
maverick
ignored
natty
ignored
oneiric
ignored
precise
not-affected
quantal
not-affected
raring
not-affected