CVE-2012-4451
Summary
| CVE | CVE-2012-4451 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-03 17:15:00 UTC |
| Updated | 2020-01-14 18:51:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 16 | All | All | All |
| Operating System | Fedoraproject | Fedora | 17 | All | All | All |
| Operating System | Fedoraproject | Fedora | 16 | All | All | All |
| Operating System | Fedoraproject | Fedora | 17 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Application | Zend | Zend Framework | All | All | All | All |
| Application | Zend | Zend Framework | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 436210 – (CVE-2012-4451) dev-php/ZendFramework: Multiple Cross-Site Scripting Vulnerabilities (CVE-2012-4451) | MISC | bugs.gentoo.org | Third Party Advisory |
| Merge branch 'security/escaper-usage' · zendframework/zendframework@27131ca · GitHub | MISC | github.com | Patch, Third Party Advisory |
| oss-sec: Re: CVE Request -- php-ZendFramework: XSS vectors in multiple Zend Framework components (ZF2012-03) | MISC | seclists.org | Mailing List, Patch, Third Party Advisory |
| Zend Framework Multiple Cross Site Scripting Vulnerabilities | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| 860738 – (CVE-2012-4451) CVE-2012-4451 php-ZendFramework: XSS vectors in multiple Zend Framework components (ZF2012-03) | MISC | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| ZF2012-03: Potential XSS Vectors in Multiple Zend Framework 2 Components - Advisories - Security - Zend Framework | MISC | framework.zend.com | Vendor Advisory |
| oss-sec: CVE Request -- php-ZendFramework: XSS vectors in multiple Zend Framework components (ZF2012-03) | MISC | seclists.org | Mailing List, Patch, Third Party Advisory |
| #688946 - zendframework: CVE-2012-4451 - Debian Bug report logs | MISC | bugs.debian.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.