CVE-2012-3238
Published Jul 9, 2012
Last updated 12 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:astaro:security_gateway_software:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "420C1976-6941-4155-A253-0F4CF42254D0", "versionEndIncluding": "8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:astaro:security_gateway:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92DE340A-A359-42F6-98FC-5105637C1DEF" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sophos:unified_threat_management_software:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A220989E-3634-4CF9-B1A0-75260DDF4121", "versionEndIncluding": "8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:sophos:unified_threat_management:110:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9D7BF2E-1DEB-474A-8DEE-0A2D1A9B1A77" }, { "criteria": "cpe:2.3:h:sophos:unified_threat_management:120:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CE59783E-6A2D-4777-9BA2-8527DA6B32BA" }, { "criteria": "cpe:2.3:h:sophos:unified_threat_management:220:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "646FEB9F-2F54-4946-9687-C2EC28144C97" }, { "criteria": "cpe:2.3:h:sophos:unified_threat_management:320:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57654458-F143-4D70-9D52-0A242F3177A1" }, { "criteria": "cpe:2.3:h:sophos:unified_threat_management:425:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6527EC0-536E-4BF0-9949-8FA4A4E64688" }, { "criteria": "cpe:2.3:h:sophos:unified_threat_management:525:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "21A9EA52-E9F1-4267-86BC-570ED1ECC7B1" }, { "criteria": "cpe:2.3:h:sophos:unified_threat_management:625:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "280976E2-D7A8-43B7-A57C-66920BC91DAB" } ], "operator": "OR" } ], "operator": "AND" } ]