CVE-2012-6662
Summary
| CVE | CVE-2012-6662 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-11-24 16:59:00 UTC |
| Updated | 2018-07-14 01:29:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Tooltip: Escape the title attribute so that it's treated as text and … · jquery/jquery-ui@f285440 · GitHub |
CONFIRM |
github.com |
Issue Tracking, Patch, Third Party Advisory |
| IBM X-Force Exchange |
XF |
exchange.xforce.ibmcloud.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| #8861 (Tooltip: XSS vulnerability in default content)
– jQuery UI |
CONFIRM |
bugs.jqueryui.com |
Issue Tracking, Vendor Advisory |
| Autocomplete demo: Combobox: Encode search term inside tooltips. Fixe… · jquery/jquery-ui@5fee6fd · GitHub |
CONFIRM |
github.com |
Issue Tracking, Patch, Third Party Advisory |
| oss-sec: old CVE assignments for JQuery 1.10.0 |
MLIST |
seclists.org |
Third Party Advisory, VDB Entry |
| Inadequate/dangerous jQuery behavior for 3rd party text/javascript responses · Issue #2432 · jquery/jquery · GitHub |
MISC |
github.com |
|
| JQuery 'combobox.html' Cross Site Scripting Vulnerability |
BID |
www.securityfocus.com |
|
| oss-sec: Re: old CVE assignments for JQuery 1.10.0 |
MLIST |
seclists.org |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| #8859 (Autocomplete: XSS in combobox demo)
– jQuery UI |
CONFIRM |
bugs.jqueryui.com |
Issue Tracking, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980932 Nodejs (npm) Security Update for jquery-ui (GHSA-qqxp-xp9v-vvx6)
- 995420 Java (Maven) Security Update for org.webjars.npm:jquery-ui (GHSA-qqxp-xp9v-vvx6)
- 995437 DotNet (Nuget) Security Update for jQuery.UI.Combined (GHSA-qqxp-xp9v-vvx6)
- 995446 Rubygems (Rubygems) Security Update for jquery-ui-rails (GHSA-qqxp-xp9v-vvx6)