{"api_version":"1","generated_at":"2026-07-23T03:39:42+00:00","cve":"CVE-2012-4950","urls":{"html":"https://cve.report/CVE-2012-4950","api":"https://cve.report/api/cve/CVE-2012-4950.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-4950","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-4950"},"summary":{"title":"CVE-2012-4950","description":"Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of error messages.","state":"PUBLISHED","assigner":"certcc","published_at":"2012-11-18 21:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79787","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79787","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/87053","name":"http://osvdb.org/87053","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/56381","name":"http://www.securityfocus.com/bid/56381","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"504 Gateway Time-out","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/802596","name":"http://www.kb.cert.org/vuls/id/802596","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#802596 - Pattern Insight 2.3 contains multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/51203","name":"http://secunia.com/advisories/51203","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA51203 - Pattern Insight Code Assurance Cross-Site Scripting and Request Forgery Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-4950","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-4950","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"4950","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"patterninsight","cpe5":"pattern_insight","cpe6":"2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T20:50:18.055Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"pattern-insight-keyword-search-xss(79787)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79787"},{"name":"VU#802596","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/802596"},{"name":"87053","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/87053"},{"name":"56381","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/56381"},{"name":"51203","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51203"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-11-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of error messages."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"pattern-insight-keyword-search-xss(79787)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79787"},{"name":"VU#802596","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/802596"},{"name":"87053","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/87053"},{"name":"56381","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/56381"},{"name":"51203","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51203"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2012-4950","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of error messages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"pattern-insight-keyword-search-xss(79787)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79787"},{"name":"VU#802596","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/802596"},{"name":"87053","refsource":"OSVDB","url":"http://osvdb.org/87053"},{"name":"56381","refsource":"BID","url":"http://www.securityfocus.com/bid/56381"},{"name":"51203","refsource":"SECUNIA","url":"http://secunia.com/advisories/51203"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2012-4950","datePublished":"2012-11-18T21:00:00.000Z","dateReserved":"2012-09-17T00:00:00.000Z","dateUpdated":"2024-08-06T20:50:18.055Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-11-18 21:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:patterninsight:pattern_insight:2.3:*:*:*:*:*:*:*","matchCriteriaId":"5193A710-0AEB-48F6-A49B-78F91A433ACA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"4950","Ordinal":"1","Title":"CVE-2012-4950","CVE":"CVE-2012-4950","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"4950","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of error messages.","Type":"Description","Title":"CVE-2012-4950"},{"CveYear":"2012","CveId":"4950","Ordinal":"2","NoteData":"2012-11-18","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"4950","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}