CVE-2012-2683 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444 as used in Red Hat Enterprise Messaging Realtime and Grid (MRG) 2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) \error message displays\ or (2) \in source HTML on certain pages.\

Reference

http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=830243 http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092543.html http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092562.html http://rhn.redhat.com/errata/RHSA-2012-1278.html http://rhn.redhat.com/errata/RHSA-2012-1281.html http://secunia.com/advisories/50660 http://www.securityfocus.com/bid/55618 https://exchange.xforce.ibmcloud.com/vulnerabilities/78772

Share on: