CVE-2012-2575
Published Sep 17, 2012
Last updated 12 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IFRAME element in the body of an HTML e-mail message.
- Source
- cret@cert.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:netwin:surgemail:6.0:a4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9D9FC1C-B907-4FEC-8FC4-7CAFDAB072AF" } ], "operator": "OR" } ] } ]