4.3
CVE-2012-5460
- EPSS 0.26%
- Published 01.08.2013 13:32:35
- Last modified 11.04.2025 00:51:21
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.
Data is provided by the National Vulnerability Database (NVD)
Juniper ≫ Secure Access Virtual Appliance Version-
Juniper ≫ Fips Secure Access 4000 Version-
Juniper ≫ Fips Secure Access 4500 Version-
Juniper ≫ Fips Secure Access 6000 Version-
Juniper ≫ Fips Secure Access 6500 Version-
Juniper ≫ Mag2600 Gateway Version-
Juniper ≫ Mag4610 Gateway Version-
Juniper ≫ Mag6610 Gateway Version-
Juniper ≫ Mag6611 Gateway Version-
Juniper ≫ Secure Access 2000 Version-
Juniper ≫ Secure Access 2500 Version-
Juniper ≫ Secure Access 4000 Version-
Juniper ≫ Secure Access 4500 Version-
Juniper ≫ Secure Access 6000 Version-
Juniper ≫ Secure Access 6500 Version-
Juniper ≫ Secure Access 700 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.26% | 0.467 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.