CVE-2012-5460
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.
Affected (19)
Products: Juniper: Ive Os, Fips Secure Access 4000, Fips Secure Access 4500, Fips Secure Access 6000, Fips Secure Access 6500, Mag2600 Gateway, Mag4610 Gateway, Mag6610 Gateway, Mag6611 Gateway, Secure Access 2000, Secure Access 2500, Secure Access 4000, Secure Access 4500, Secure Access 6000, Secure Access 6500, Secure Access 700, Secure Access Virtual Appliance
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
References (4)
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.