CVE-2012-2641

Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3 allows remote attackers to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
zenphotozenphoto
𝑥
≤ 1.4.2
zenphotozenphoto
0.9
zenphotozenphoto
1.0:beta
zenphotozenphoto
1.0.1:beta
zenphotozenphoto
1.0.4
zenphotozenphoto
1.0.5
zenphotozenphoto
1.0.6
zenphotozenphoto
1.1
zenphotozenphoto
1.1.1
zenphotozenphoto
1.1.2
zenphotozenphoto
1.1.3
zenphotozenphoto
1.1.7
zenphotozenphoto
1.2.5
zenphotozenphoto
1.3
zenphotozenphoto
1.3.1.2
𝑥
= Vulnerable software versions