CVE-2012-4932
在 stable-2012-1-CIS3000 之前的 SimpleInvoices 版本中存在多个跨站脚本(XSS)漏洞,远程攻击者可借此注入任意 Web 脚本或 HTML,具体途径包括:(1) index.php 中 manage 操作的 having 参数;(2) Add User 操作中的 Email...
- 已发布
- 2012年12月28日
- 已更新
- 2024年9月16日
- 分配 CNA
- mitre
- 观察到的证据
- 2012年12月10日
初级CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N低 · 未来 30 天
- 百分位
- 69.1%
- 型号日期
- 2026年9月21日
EPSS 是统计估计,而不是确定性或影响衡量标准。将其与 CVSS、KEV 状态、暴露程度和您的环境相结合。
总结
在 stable-2012-1-CIS3000 之前的 SimpleInvoices 版本中存在多个跨站脚本(XSS)漏洞,远程攻击者可借此注入任意 Web 脚本或 HTML,具体途径包括:(1) index.php 中 manage 操作的 having 参数;(2) Add User 操作中的 Email 字段;(3) Add Customer 操作中的 Customer Name 字段;Add Biller 操作中的 (4) Street address、(5) Street address 2、(6) City、(7) Zip code、(8) State、(9) Country、(10) Mobile Phone、(11) Phone、(12) Fax、(13) Email、(14) PayPal business name、(15) PayPal notify url、(16) PayPal return url、(17) Eway customer ID、(18) Custom field 1、(19) Custom field 2、(20) Custom field 3 或 (21) Custom field 4 字段;(22) Add Invoice 操作中的 Customer 字段;Process Payment 操作中的 (23) Invoice 或 (24) Notes 字段;(25) Payment Types 操作中的 Payment type description 字段;(26) Invoice Preferences 操作中的 Description 字段;(27) Manage Products 操作中的 Description 字段;或 (28) Tax Rates 操作中的 Description 字段。
来源
1tommccredie · php · 2012年12月10日
负责任的使用
仅在您拥有或有权测试的系统上使用漏洞信息。 Kitploit 链接到公共研究元数据,并且不存储漏洞代码或恶意负载。