CVE-2012-0790

UnknownEPSS 1.34%

Last modified

CVE-2012-0790 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.

Description

Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.

Metrics

EPSS Probability
1.34%

67.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
OetikerSmokeping<= 2.6.6
OetikerSmokeping0.99.5
OetikerSmokeping0.99.6
OetikerSmokeping0.99.7
OetikerSmokeping0.99.8
OetikerSmokeping0.99.9
OetikerSmokeping0.99.10
OetikerSmokeping0.99.11
OetikerSmokeping0.99.12
OetikerSmokeping0.99.13
OetikerSmokeping0.99.14
OetikerSmokeping0.99.15
OetikerSmokeping0.99.16
OetikerSmokeping0.99.17
OetikerSmokeping0.99.18
OetikerSmokeping1.0
OetikerSmokeping1.1
OetikerSmokeping1.2
OetikerSmokeping1.3
OetikerSmokeping1.4
OetikerSmokeping1.5
OetikerSmokeping1.6
OetikerSmokeping1.7
OetikerSmokeping1.8
OetikerSmokeping1.9
OetikerSmokeping1.10
OetikerSmokeping1.11
OetikerSmokeping1.12
OetikerSmokeping1.13
OetikerSmokeping1.14
OetikerSmokeping1.15
OetikerSmokeping1.16
OetikerSmokeping1.17
OetikerSmokeping1.18
OetikerSmokeping1.19
OetikerSmokeping1.20
OetikerSmokeping1.21
OetikerSmokeping1.22
OetikerSmokeping1.23
OetikerSmokeping1.24
OetikerSmokeping1.25
OetikerSmokeping1.26
OetikerSmokeping1.27
OetikerSmokeping1.28
OetikerSmokeping1.29
OetikerSmokeping1.30
OetikerSmokeping1.31
OetikerSmokeping1.34
OetikerSmokeping1.36
OetikerSmokeping1.37

Showing 50 of 90 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-0790?
Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.
How severe is CVE-2012-0790?
Severity scoring for CVE-2012-0790 is pending analysis. The EPSS model estimates a 1.34% probability of exploitation in the next 30 days.
How do I fix CVE-2012-0790?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-0790?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST