CVE-2012-1561
Last modified
CVE-2012-1561 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "checkbox and radio button functionalities.". EPSS estimates a 3.01% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "checkbox and radio button functionalities."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Danielb | Finder | 6.x-1.0 | — |
| Danielb | Finder | 6.x-1.1 | — |
| Danielb | Finder | 6.x-1.2 | — |
| Danielb | Finder | 6.x-1.3 | — |
| Danielb | Finder | 6.x-1.4 | — |
| Danielb | Finder | 6.x-1.5 | — |
| Danielb | Finder | 6.x-1.6 | — |
| Danielb | Finder | 6.x-1.7 | — |
| Danielb | Finder | 6.x-1.8 | — |
| Danielb | Finder | 6.x-1.9 | — |
| Danielb | Finder | 6.x-1.10 | — |
| Danielb | Finder | 6.x-1.11 | — |
| Danielb | Finder | 6.x-1.12 | — |
| Danielb | Finder | 6.x-1.13 | — |
| Danielb | Finder | 6.x-1.14 | — |
| Danielb | Finder | 6.x-1.15 | — |
| Danielb | Finder | 6.x-1.16 | — |
| Danielb | Finder | 6.x-1.17 | — |
| Danielb | Finder | 6.x-1.18 | — |
| Danielb | Finder | 6.x-1.19 | — |
| Danielb | Finder | 6.x-1.20 | — |
| Danielb | Finder | 6.x-1.21 | — |
| Danielb | Finder | 6.x-1.23 | — |
| Danielb | Finder | 6.x-1.24 | — |
| Danielb | Finder | 6.x-1.25 | — |
| Danielb | Finder | 6.x-1.x-dev | — |
| Danielb | Finder | 7.x-1.0 | — |
| Danielb | Finder | 7.x-1.1 | — |
| Danielb | Finder | 7.x-1.2 | — |
| Danielb | Finder | 7.x-1.3 | — |
| Danielb | Finder | 7.x-1.4 | — |
| Danielb | Finder | 7.x-1.5 | — |
| Danielb | Finder | 7.x-1.6 | — |
| Danielb | Finder | 7.x-1.x | Dev |
| Danielb | Finder | 7.x-2.0 | Alpha1 |
| Danielb | Finder | 7.x-2.x | Dev |
References
- http://secunia.com/advisories/47943Vendor Advisory
- https://drupal.org/node/1432970Patch, Vendor Advisory
- http://secunia.com/advisories/47943Vendor Advisory
- https://drupal.org/node/1432970Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1561?
How severe is CVE-2012-1561?
How do I fix CVE-2012-1561?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-1543Unspecified vulnerability in the JavaFX component in Oracle …
- CVE-2012-1544Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2012-1545Microsoft Internet Explorer 6 through 9, and 10 Consumer Pre…
- CVE-2012-1556Cross-site scripting (XSS) vulnerability in Synology Photo S…
- CVE-2012-1557SQL injection vulnerability in admin/plib/api-rpc/Agent.php …
- CVE-2012-1558yaSSL CyaSSL before 2.0.8 allows remote attackers to cause a…
- CVE-2012-1562Joomla! core before 2.5.3 allows unauthorized password chang…7.5
- CVE-2012-1563Joomla! before 2.5.3 allows Admin Account Creation.7.5
- CVE-2012-1564Cross-site scripting (XSS) vulnerability in administration/c…
- CVE-2012-1565Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4…
- CVE-2012-1566LinuxMint as of 2012-03-19 has temporary file creation vulne…7.5
- CVE-2012-1567LinuxMint as of 2012-03-19 has temporary file creation vulne…7.5
Are you affected by CVE-2012-1561?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
