CVE-2012-1639
Published Oct 1, 2012
Last updated 7 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 3.5
- Impact score
- 2.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:commerceguys:commerce:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04D29FF2-2D39-4DE7-8965-9DD40B8E27DC", "versionEndIncluding": "7.x-1.1" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36BE5A7F-A97B-41A2-ADE6-F4D64CE7C046" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D64B0AFA-E9EE-41F9-81C3-6A6BD039021A" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4261C160-8926-4DAC-B2BC-A63D67305144" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB5E1423-1492-45CC-83FC-9D4A5A0F98EE" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD023352-F7CE-4D2C-A21B-8CF34F1450BB" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CDA3BB6E-7F11-49EE-B028-989230DBACDD" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0252DCA1-8E3A-4E0A-923C-BC03D32D7C05" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2ABE5EA8-E848-48BA-A4D3-235DF0B47923" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A93AF10B-0D25-4749-8FE3-91F02F9B7F5A" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BF49E58-1B39-4547-9A7A-F87D45DD05B7" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "872145E2-7B5D-4147-9A1A-B8F3DE95DADC" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B651A2F-2097-4375-B251-AE354B95D06C" }, { "criteria": "cpe:2.3:a:commerceguys:commerce:7.x-1.x:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31E1F368-B3AD-421E-894D-DFB45B812A4C" } ], "operator": "OR" } ], "operator": "AND" } ]