CVE-2012-2235

Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to index.php, which is not properly handled in an error message.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
sitrackersupport_incident_tracker
𝑥
≤ 3.65
sitrackersupport_incident_tracker
1.8.00
sitrackersupport_incident_tracker
2.8.00
sitrackersupport_incident_tracker
3.00
sitrackersupport_incident_tracker
3.00:beta1
sitrackersupport_incident_tracker
3.00:beta2
sitrackersupport_incident_tracker
3.00:beta3
sitrackersupport_incident_tracker
3.01
sitrackersupport_incident_tracker
3.02
sitrackersupport_incident_tracker
3.03
sitrackersupport_incident_tracker
3.03a:a
sitrackersupport_incident_tracker
3.04a:a
sitrackersupport_incident_tracker
3.05
sitrackersupport_incident_tracker
3.6
sitrackersupport_incident_tracker
3.06
sitrackersupport_incident_tracker
3.07
sitrackersupport_incident_tracker
3.45
sitrackersupport_incident_tracker
3.45:beta1
sitrackersupport_incident_tracker
3.50
sitrackersupport_incident_tracker
3.50:beta1
sitrackersupport_incident_tracker
3.51
sitrackersupport_incident_tracker
3.60
sitrackersupport_incident_tracker
3.61
sitrackersupport_incident_tracker
3.62
sitrackersupport_incident_tracker
3.63
sitrackersupport_incident_tracker
3.63:beta1
sitrackersupport_incident_tracker
3.64
sitrackersupport_incident_tracker
4.8.00
sitrackersupport_incident_tracker
7.8.00
sitrackersupport_incident_tracker
8.8.00
sitrackersupport_incident_tracker
9.8.00
sitrackersupport_incident_tracker
10.8.00
sitrackersupport_incident_tracker
11.8.00
sitrackersupport_incident_tracker
14.8.00
sitrackersupport_incident_tracker
16.8.00
sitrackersupport_incident_tracker
17.8.00
sitrackersupport_incident_tracker
18.8.00
sitrackersupport_incident_tracker
21.8.00
sitrackersupport_incident_tracker
31.07.00
𝑥
= Vulnerable software versions