Vulnerability Database

314,433

Total vulnerabilities in the database

CVE-2012-1039

Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.

  • Published: Mar 19, 2012
  • Updated: Nov 9, 2025
  • CVE: CVE-2012-1039
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
dotclear / dotclear 1.2.3 1.2.3.x
dotclear / dotclear 2.0-beta_7 2.0-beta_7.x
dotclear / dotclear 2.0-beta_5.4 2.0-beta_5.4.x
dotclear / dotclear 2.2.1 2.2.1.x
dotclear / dotclear 2.0-beta_5.2 2.0-beta_5.2.x
dotclear / dotclear 2.1 2.1.x
dotclear / dotclear 2.0.1 2.0.1.x
dotclear / dotclear 2.0.2 2.0.2.x
dotclear / dotclear 2.1.4 2.1.4.x
dotclear / dotclear 2.0 2.0.x
dotclear / dotclear 2.2.2 2.2.2.x
dotclear / dotclear 1.2.5 1.2.5.x
dotclear / dotclear 2.0-beta_3 2.0-beta_3.x
dotclear / dotclear 2.3.0 2.3.0.x
dotclear / dotclear 2.1.1 2.1.1.x
dotclear / dotclear 1.2.2 1.2.2.x
dotclear / dotclear - 2.3.1.x
dotclear / dotclear 2.0-beta_4 2.0-beta_4.x
dotclear / dotclear 2.0-rc1 2.0-rc1.x
dotclear / dotclear 1.2.6 1.2.6.x
dotclear / dotclear 2.1.5 2.1.5.x
dotclear / dotclear 2.1.7 2.1.7.x
dotclear / dotclear 2.0-beta_2 2.0-beta_2.x
dotclear / dotclear 2.2.3 2.2.3.x
dotclear / dotclear 2.0-beta_6 2.0-beta_6.x
dotclear / dotclear 1.2.7 1.2.7.x
dotclear / dotclear 2.0-rc2 2.0-rc2.x
dotclear / dotclear 2.2 2.2.x
dotclear / dotclear 1.2.4 1.2.4.x
dotclear / dotclear 2.1.6 2.1.6.x
dotclear / dotclear 2.1.3 2.1.3.x
dotclear / dotclear 1.2.1 1.2.1.x
dotclear / dotclear 1.2.8 1.2.8.x