{ "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2012-2112", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6.x before 4.6.8, and 4.7 allows remote attackers to inject arbitrary web script or HTML via exception messages." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "[TYPO3-announce] 20120417 Cross-Site Scripting Vulnerability in TYPO3 Core", "refsource": "MLIST", "url": "http://lists.typo3.org/pipermail/typo3-announce/2012/000241.html" }, { "name": "exceptionhandler-exceptionmessages-xss(74920)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/74920" }, { "name": "53047", "refsource": "BID", "url": "http://www.securityfocus.com/bid/53047" }, { "name": "[TYPO3-announce] 20120417 Announcing TYPO3 4.4.15, 4.5.15 and 4.6.8", "refsource": "MLIST", "url": "http://lists.typo3.org/pipermail/typo3-announce/2012/000242.html" }, { "name": "[oss-security] 20120417 CVE-request: TYPO3-CORE-SA-2012-002 XSS in TYPO3 Core", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2012/04/17/5" }, { "name": "[oss-security] 20120417 Re: CVE-request: TYPO3-CORE-SA-2012-002 XSS in TYPO3 Core", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2012/04/18/1" }, { "name": "DSA-2455", "refsource": "DEBIAN", "url": "http://www.debian.org/security/2012/dsa-2455" }, { "name": "http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-002/", "refsource": "CONFIRM", "url": "http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-002/" } ] } }