{"api_version":"1","generated_at":"2026-07-23T03:22:48+00:00","cve":"CVE-2012-4451","urls":{"html":"https://cve.report/CVE-2012-4451","api":"https://cve.report/api/cve/CVE-2012-4451.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-4451","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-4451"},"summary":{"title":"CVE-2012-4451","description":"Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\\PubSubHubbub, (3) Log\\Formatter\\Xml, (4) Tag\\Cloud\\Decorator, (5) Uri, (6) View\\Helper\\HeadStyle, (7) View\\Helper\\Navigation\\Sitemap, or (8) View\\Helper\\Placeholder\\Container\\AbstractStandalone, related to Escaper.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2020-01-03 17:15:00","updated_at":"2020-01-14 18:51:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://bugs.gentoo.org/show_bug.cgi?id=436210","name":"https://bugs.gentoo.org/show_bug.cgi?id=436210","refsource":"MISC","tags":["Third Party Advisory"],"title":"436210 – (CVE-2012-4451) dev-php/ZendFramework: Multiple Cross-Site Scripting Vulnerabilities (CVE-2012-4451)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/zendframework/zf2/commit/27131ca9520bdf1d4c774c71459eba32f2b10733","name":"https://github.com/zendframework/zf2/commit/27131ca9520bdf1d4c774c71459eba32f2b10733","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Merge branch 'security/escaper-usage' · zendframework/zendframework@27131ca · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/oss-sec/2012/q3/573","name":"http://seclists.org/oss-sec/2012/q3/573","refsource":"MISC","tags":["Mailing List","Patch","Third Party Advisory"],"title":"oss-sec: Re: CVE Request -- php-ZendFramework: XSS vectors in multiple Zend Framework components (ZF2012-03)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/55636","name":"http://www.securityfocus.com/bid/55636","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"Zend Framework Multiple Cross Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=860738","name":"https://bugzilla.redhat.com/show_bug.cgi?id=860738","refsource":"MISC","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"860738 – (CVE-2012-4451) CVE-2012-4451 php-ZendFramework: XSS vectors in multiple Zend Framework components (ZF2012-03)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://framework.zend.com/security/advisory/ZF2012-03","name":"http://framework.zend.com/security/advisory/ZF2012-03","refsource":"MISC","tags":["Vendor Advisory"],"title":"ZF2012-03: Potential XSS Vectors in Multiple Zend Framework 2 Components - Advisories - Security - Zend Framework","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/oss-sec/2012/q3/571","name":"http://seclists.org/oss-sec/2012/q3/571","refsource":"MISC","tags":["Mailing List","Patch","Third Party Advisory"],"title":"oss-sec: CVE Request -- php-ZendFramework: XSS vectors in multiple Zend Framework components (ZF2012-03)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688946#10","name":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688946#10","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"#688946 - zendframework: CVE-2012-4451 - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-4451","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-4451","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"4451","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4451","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"17","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4451","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4451","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"17","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4451","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4451","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4451","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zend","cpe5":"zend_framework","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4451","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zend","cpe5":"zend_framework","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2012-4451","STATE":"PUBLIC"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\\PubSubHubbub, (3) Log\\Formatter\\Xml, (4) Tag\\Cloud\\Decorator, (5) Uri, (6) View\\Helper\\HeadStyle, (7) View\\Helper\\Navigation\\Sitemap, or (8) View\\Helper\\Placeholder\\Container\\AbstractStandalone, related to Escaper."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Cross-Site Scripting"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Zend Technologies","product":{"product_data":[{"product_name":"Zend Framework","version":{"version_data":[{"version_value":"2.0.x before 2.0.1"}]}}]}}]}},"references":{"reference_data":[{"refsource":"MISC","name":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688946#10","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688946#10"},{"refsource":"MISC","name":"https://bugs.gentoo.org/show_bug.cgi?id=436210","url":"https://bugs.gentoo.org/show_bug.cgi?id=436210"},{"refsource":"MISC","name":"http://seclists.org/oss-sec/2012/q3/571","url":"http://seclists.org/oss-sec/2012/q3/571"},{"refsource":"MISC","name":"http://seclists.org/oss-sec/2012/q3/573","url":"http://seclists.org/oss-sec/2012/q3/573"},{"refsource":"MISC","name":"http://framework.zend.com/security/advisory/ZF2012-03","url":"http://framework.zend.com/security/advisory/ZF2012-03"},{"refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=860738","url":"https://bugzilla.redhat.com/show_bug.cgi?id=860738"},{"refsource":"MISC","name":"https://github.com/zendframework/zf2/commit/27131ca9520bdf1d4c774c71459eba32f2b10733","url":"https://github.com/zendframework/zf2/commit/27131ca9520bdf1d4c774c71459eba32f2b10733"},{"refsource":"MISC","name":"http://www.securityfocus.com/bid/55636","url":"http://www.securityfocus.com/bid/55636"}]}},"nvd":{"publishedDate":"2020-01-03 17:15:00","lastModifiedDate":"2020-01-14 18:51:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"4451","Ordinal":"57208","Title":"CVE-2012-4451","CVE":"CVE-2012-4451","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"4451","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\\PubSubHubbub, (3) Log\\Formatter\\Xml, (4) Tag\\Cloud\\Decorator, (5) Uri, (6) View\\Helper\\HeadStyle, (7) View\\Helper\\Navigation\\Sitemap, or (8) View\\Helper\\Placeholder\\Container\\AbstractStandalone, related to Escaper.","Type":"Description","Title":null},{"CveYear":"2012","CveId":"4451","Ordinal":"2","NoteData":"2020-01-03","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"4451","Ordinal":"3","NoteData":"2020-01-03","Type":"Other","Title":"Modified"}]}}}