CVE-2012-1293

UnknownEPSS 2.56%

Last modified

CVE-2012-1293 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20111129-2 allow remote attackers to inject arbitrary web script or HTML via the (1) to or (2) from parameters.. EPSS estimates a 2.56% chance of exploitation in the next 30 days.

Description

Multiple cross-site scripting (XSS) vulnerabilities in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20111129-2 allow remote attackers to inject arbitrary web script or HTML via the (1) to or (2) from parameters.

Metrics

EPSS Probability
2.56%

83.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Ulli HorlacherFex<= 20111129
Ulli HorlacherFex20110609
Ulli HorlacherFex20110610
Ulli HorlacherFex20110614
Ulli HorlacherFex20110615
Ulli HorlacherFex20110616
Ulli HorlacherFex20110621
Ulli HorlacherFex20110622
Ulli HorlacherFex20110627
Ulli HorlacherFex20110630
Ulli HorlacherFex20110701
Ulli HorlacherFex20110714
Ulli HorlacherFex20110716
Ulli HorlacherFex20110722
Ulli HorlacherFex20110726
Ulli HorlacherFex20110727
Ulli HorlacherFex20110730
Ulli HorlacherFex20110731
Ulli HorlacherFex20110803
Ulli HorlacherFex20110807
Ulli HorlacherFex20110808
Ulli HorlacherFex20110809
Ulli HorlacherFex20110810
Ulli HorlacherFex20110811
Ulli HorlacherFex20110813
Ulli HorlacherFex20110826
Ulli HorlacherFex20110829
Ulli HorlacherFex20110830
Ulli HorlacherFex20110901
Ulli HorlacherFex20110905
Ulli HorlacherFex20110906
Ulli HorlacherFex20110907
Ulli HorlacherFex20110919
Ulli HorlacherFex20110920
Ulli HorlacherFex20110921
Ulli HorlacherFex20110930
Ulli HorlacherFex20111003
Ulli HorlacherFex20111005
Ulli HorlacherFex20111013
Ulli HorlacherFex20111028
Ulli HorlacherFex20111102
Ulli HorlacherFex20111108
Ulli HorlacherFex20111115

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-1293?
Multiple cross-site scripting (XSS) vulnerabilities in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20111129-2 allow remote attackers to inject arbitrary web script or HTML via the (1) to or (2) from parameters.
How severe is CVE-2012-1293?
Severity scoring for CVE-2012-1293 is pending analysis. The EPSS model estimates a 2.56% probability of exploitation in the next 30 days.
How do I fix CVE-2012-1293?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-1293?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST