CVE-2012-4000

Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject arbitrary web script or HTML via textinputs array parameters.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
ckeditorfckeditor
𝑥
≤ 2.6.7
ckeditorfckeditor
0.8:beta
ckeditorfckeditor
0.8.5:beta
ckeditorfckeditor
0.9.0:beta
ckeditorfckeditor
0.9.1:beta
ckeditorfckeditor
0.9.2:beta
ckeditorfckeditor
0.9.3:beta
ckeditorfckeditor
0.9.4:beta
ckeditorfckeditor
0.9.5:beta
ckeditorfckeditor
1.0
ckeditorfckeditor
1.0:fc
ckeditorfckeditor
1.0:rc1
ckeditorfckeditor
1.1
ckeditorfckeditor
1.2
ckeditorfckeditor
1.2.2
ckeditorfckeditor
1.2.4
ckeditorfckeditor
1.3
ckeditorfckeditor
1.3.1
ckeditorfckeditor
1.4
ckeditorfckeditor
1.5
ckeditorfckeditor
1.6
ckeditorfckeditor
2.0
ckeditorfckeditor
2.0:beta1
ckeditorfckeditor
2.0:beta2
ckeditorfckeditor
2.0:fc
ckeditorfckeditor
2.0:rc1
ckeditorfckeditor
2.0:rc2
ckeditorfckeditor
2.0:rc3
ckeditorfckeditor
2.1
ckeditorfckeditor
2.1.1
ckeditorfckeditor
2.2
ckeditorfckeditor
2.3
ckeditorfckeditor
2.3:beta
ckeditorfckeditor
2.3.1
ckeditorfckeditor
2.3.2
ckeditorfckeditor
2.3.3
ckeditorfckeditor
2.4
ckeditorfckeditor
2.4.1
ckeditorfckeditor
2.4.2
ckeditorfckeditor
2.4.3
ckeditorfckeditor
2.5
ckeditorfckeditor
2.5:beta
ckeditorfckeditor
2.5.1
ckeditorfckeditor
2.6:beta
ckeditorfckeditor
2.6:rc
ckeditorfckeditor
2.6.1
ckeditorfckeditor
2.6.2
ckeditorfckeditor
2.6.3
ckeditorfckeditor
2.6.3:beta
ckeditorfckeditor
2.6.4
ckeditorfckeditor
2.6.4:beta
ckeditorfckeditor
2.6.4.1
ckeditorfckeditor
2.6.5
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fckeditor
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
Fixed 1:2.6.6-1squeeze1build0.12.04.1
released
oneiric
Fixed 1:2.6.6-1squeeze1build0.11.10.1
released
natty
Fixed 1:2.6.6-1squeeze1build0.11.04.1
released
lucid
ignored
hardy
ignored