Vulnerability Details CVE-2012-5700
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in blocks/loginbox/loginbox.template.php to index.php. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.037
EPSS Ranking 87.5%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2012-5700
-
cpe:2.3:a:babygekko:baby_gekko:*
-
cpe:2.3:a:babygekko:baby_gekko:0.90
-
cpe:2.3:a:babygekko:baby_gekko:0.91
-
cpe:2.3:a:babygekko:baby_gekko:0.98
-
cpe:2.3:a:babygekko:baby_gekko:0.99
-
cpe:2.3:a:babygekko:baby_gekko:1.0.0
-
cpe:2.3:a:babygekko:baby_gekko:1.0.1
-
cpe:2.3:a:babygekko:baby_gekko:1.1.0
-
cpe:2.3:a:babygekko:baby_gekko:1.1.1
-
cpe:2.3:a:babygekko:baby_gekko:1.1.2
-
cpe:2.3:a:babygekko:baby_gekko:1.1.3
-
cpe:2.3:a:babygekko:baby_gekko:1.1.4
-
cpe:2.3:a:babygekko:baby_gekko:1.1.5
-
cpe:2.3:a:babygekko:baby_gekko:1.2.0
-
cpe:2.3:a:babygekko:baby_gekko:1.2.2