Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-1212

Cross-site scripting (XSS) vulnerability in the smwfOnSfSetTargetName function in extensions/SMWHalo/includes/SMW_Initialize.php in Semantic Enterprise Wiki (SMW+) 1.5.6, 1.6.0_2 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter to index.php/Special:FormEdit. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.7%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2012-1212
  • Smwplus » Smw+ » Version: 1.4.4
    cpe:2.3:a:smwplus:smw+:1.4.4
  • Smwplus » Smw+ » Version: 1.4.5
    cpe:2.3:a:smwplus:smw+:1.4.5
  • Smwplus » Smw+ » Version: 1.4.6
    cpe:2.3:a:smwplus:smw+:1.4.6
  • Smwplus » Smw+ » Version: 1.5.0
    cpe:2.3:a:smwplus:smw+:1.5.0
  • Smwplus » Smw+ » Version: 1.5.1
    cpe:2.3:a:smwplus:smw+:1.5.1
  • Smwplus » Smw+ » Version: 1.5.2
    cpe:2.3:a:smwplus:smw+:1.5.2
  • Smwplus » Smw+ » Version: 1.5.3
    cpe:2.3:a:smwplus:smw+:1.5.3
  • Smwplus » Smw+ » Version: 1.5.6
    cpe:2.3:a:smwplus:smw+:1.5.6
  • Smwplus » Smw+ » Version: 1.5.6-1
    cpe:2.3:a:smwplus:smw+:1.5.6-1
  • Smwplus » Smw+ » Version: 1.6.0
    cpe:2.3:a:smwplus:smw+:1.6.0
  • Smwplus » Smw+ » Version: 1.6.0_2
    cpe:2.3:a:smwplus:smw+:1.6.0_2


Contact Us

Shodan ® - All rights reserved