4.3

CVE-2012-2648

Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16 and earlier for iOS on the iPad, and 3.15.1 and earlier for iOS on the iPhone and iPod touch, allows remote attackers to inject arbitrary web script or HTML via vectors involving use of this app in conjunction with a web browser.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoodiwareGoodreader Update- SwPlatformiphone_os Version <= 3.16
   AppleIpad
GoodiwareGoodreader Version1.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.2 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.3 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.4 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.5 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.5.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.6 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.7 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.7.4 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.8 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version2.8.4 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.0.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.0.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.0.2 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.0.3 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.1.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.1.2 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.2.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.3.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.3.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.4.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.4.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.5.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.5.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.6.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.6.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.7.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.7.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.8.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.9.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.10.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.10.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.10.2 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.10.3 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.11.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.11.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.12.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.13.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.13.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.14.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.14.2 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.15.0 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Version3.15.1 Update- SwPlatformiphone_os
   AppleIpad
GoodiwareGoodreader Update- SwPlatformiphone_os Version <= 3.15.1
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version1.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.2 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.3 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.4 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.5 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.5.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.6 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.7 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.8.2 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version2.8.5 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.0.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.0.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.0.2 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.0.3 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.2.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.2.3 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.3.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.3.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.4.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.4.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.5.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.5.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.6.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.6.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.7.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.7.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.8.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.9.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.10.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.10.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.10.2 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.10.3 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.11.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.11.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.12.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.13.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.13.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.14.1 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
GoodiwareGoodreader Version3.15.0 Update- SwPlatformiphone_os
   AppleIpod Touch
   AppleiPhone OS
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.422
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.