Multiple cross-site scripting (XSS) vulnerabilities in GreenBrowser 6.1.0117 and 6.1.0216...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in GreenBrowser 6.1.0117 and 6.1.0216 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in an about: page or (2) the last visited URL in the LastVisitWriteEn function in function.js.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-5906
Credits & Attribution
No credits recorded in the NVD database.
References
- http://packetstormsecurity.org/files/111252/GreenBrowser-6.1.x-Cross-Site-Scripting.html
- http://secunia.com/advisories/48559
- http://lostmon.blogspot.com/2012/03/greenbrowser-about-dialog-xss-and.html
- http://www.securityfocus.com/bid/52767
- http://osvdb.org/80636
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74474
Affected Vendor
morequick
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.