CVE-2012-2099
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.5%
from disclosure to weapon0 days
Published on NVDJan 24
1st PoCMar 12
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) search field, or the (2) Author or (3) select_sort parameters in an advanced search.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/36948exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/36947⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/bugtraq/2012-03/0046.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/73985http://www.darksecurity.de/advisories/2012/SSCHADV2012-005.txthttp://www.openwall.com/lists/oss-security/2012/04/12/12http://www.openwall.com/lists/oss-security/2012/04/12/5http://www.osvdb.org/80838http://www.osvdb.org/80839http://www.securityfocus.com/bid/52425http://www.wikidforum.com/forum/forum-software_29/wikidforum-support_31/sschadv2012-005-unfixed-xss-and-sql-injection-security-vulnerabilities_188.html