Vulnerability Details CVE-2012-0933
Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_colors.asp, (2) admin_config.asp, and (3) admin_cat_add.asp in admin/.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.078
EPSS Ranking 91.5%
CVSS Severity
CVSS v2 Score 2.6
Products affected by CVE-2012-0933
-
cpe:2.3:a:acidcat:acidcat_cms:3.5.1
-
cpe:2.3:a:acidcat:acidcat_cms:3.5.2
-
cpe:2.3:a:acidcat:acidcat_cms:3.5.6