CVE-2012-1110
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
06/09/2012
Last modified:
11/04/2025
Description
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) email, (3) email2, (4) f17_zip, or (5) agree parameter to join.php; (6) PATH_INFO, (7) st, (8) f17_city, (9) f17_country, (10) f17_state, (11) f17_zip, (12) f19, (13) wphoto, (14) search, or (15) v parameter to search.php; (16) PATH_INFO or (17) st parameter to photo_search.php; or (18) return parameter to photo_view.php.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:datemill:etano:*:*:*:*:*:*:*:* | 1.22 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0013.html
- http://secunia.com/advisories/48165
- http://www.openwall.com/lists/oss-security/2012/03/05/15
- http://www.openwall.com/lists/oss-security/2012/03/05/21
- http://www.osvdb.org/79827
- http://www.osvdb.org/79828
- http://www.osvdb.org/79829
- http://www.osvdb.org/79830
- http://www.securityfocus.com/bid/52295
- http://yehg.net/lab/pr0js/advisories/%5Betano_1.2.x%5D_xss
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73669
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0013.html
- http://secunia.com/advisories/48165
- http://www.openwall.com/lists/oss-security/2012/03/05/15
- http://www.openwall.com/lists/oss-security/2012/03/05/21
- http://www.osvdb.org/79827
- http://www.osvdb.org/79828
- http://www.osvdb.org/79829
- http://www.osvdb.org/79830
- http://www.securityfocus.com/bid/52295
- http://yehg.net/lab/pr0js/advisories/%5Betano_1.2.x%5D_xss
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73669



