{"api_version":"1","generated_at":"2026-07-23T04:58:44+00:00","cve":"CVE-2012-1825","urls":{"html":"https://cve.report/CVE-2012-1825","api":"https://cve.report/api/cve/CVE-2012-1825.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-1825","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-1825"},"summary":{"title":"CVE-2012-1825","description":"Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a forgotpass action or (2) the username parameter.","state":"PUBLISHED","assigner":"certcc","published_at":"2012-06-11 23:55:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/815532","name":"http://www.kb.cert.org/vuls/id/815532","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"Vulnerability Note VU#815532 - ForeScout CounterACT reflected XSS vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/MAPG-8TWMEJ","name":"http://www.kb.cert.org/vuls/id/MAPG-8TWMEJ","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"ForeScout Information for VU#815532","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-1825","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-1825","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"1825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"forescout","cpe5":"counteract","cpe6":"6.3.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"1825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"forescout","cpe5":"counteract","cpe6":"6.3.4.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T19:08:38.689Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#815532","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/815532"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/MAPG-8TWMEJ"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a forgotpass action or (2) the username parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2012-06-11T23:00:00.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"VU#815532","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/815532"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kb.cert.org/vuls/id/MAPG-8TWMEJ"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2012-1825","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a forgotpass action or (2) the username parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#815532","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/815532"},{"name":"http://www.kb.cert.org/vuls/id/MAPG-8TWMEJ","refsource":"CONFIRM","url":"http://www.kb.cert.org/vuls/id/MAPG-8TWMEJ"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2012-1825","datePublished":"2012-06-11T23:00:00.000Z","dateReserved":"2012-03-21T00:00:00.000Z","dateUpdated":"2024-09-17T04:04:35.639Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-06-11 23:55:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:forescout:counteract:6.3.3.2:*:*:*:*:*:*:*","matchCriteriaId":"7BC668C9-2DED-453F-A7B7-0D484CCB25FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:forescout:counteract:6.3.4.10:*:*:*:*:*:*:*","matchCriteriaId":"44A66E6D-EDD2-47F0-A799-AEDBD5E9F56C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"1825","Ordinal":"1","Title":"CVE-2012-1825","CVE":"CVE-2012-1825","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"1825","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a forgotpass action or (2) the username parameter.","Type":"Description","Title":"CVE-2012-1825"},{"CveYear":"2012","CveId":"1825","Ordinal":"2","NoteData":"2012-06-11","Type":"Other","Title":"Published"}]}}}