Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-1507

EPSS 9.54% · P93
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-1507

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to templates/hrfunct/emppop.php, or (3) uri parameter to index.php.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OrangeHRM 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OrangeHRM是美国OrangeHRM公司的一套全面的人力资源管理系统(HRM)。该系统支持雇员资料管理、员工自服务、考勤等。 OrangeHRM 2.7之前版本中存在跨站脚本漏洞,该漏洞源于plugins/ajaxCalls/haltResumeHsp.php脚本没有充分过滤‘newHspStatus’参数,templates/hrfunct/emppop.php脚本没有充分过滤‘sortOrder1’参数,index.php脚本没有充分过滤‘uri’参数。远程攻击者可利用该漏洞注入任意Web脚本或
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-1507

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-1507

Please Login to view more intelligence information

Same Patch Batch · n/a · 2014-09-17 · 32 CVEs total

CVE-2014-0568Adobe Reader和Acrobat 安全漏洞
CVE-2014-5918Android Secret Circle - talk freely应用程序加密问题漏洞
CVE-2014-5917Android Slideshow 365应用程序加密问题漏洞
CVE-2014-5916Android Minha Oi应用程序加密问题漏洞
CVE-2014-5915Android Tigo Copa Mundial FIFA 2014应用程序加密问题漏洞
CVE-2014-5914Android Finansbank Cep Subesi应用程序加密问题漏洞
CVE-2014-5913Android Allies in War应用程序加密问题漏洞
CVE-2014-5912Android InNote应用程序加密问题漏洞
CVE-2014-5911Android Free App Icons & Icon Packs应用程序加密问题漏洞
CVE-2014-5910Android Dog Whistle应用程序加密问题漏洞
CVE-2014-5909Android watcha应用程序加密问题漏洞
CVE-2014-5908Android Kmart应用程序加密问题漏洞
CVE-2014-5907Android Pet Salon应用程序加密问题漏洞
CVE-2014-5906Android Lil Wayne Slots: FREE SLOTS应用程序加密问题漏洞
CVE-2014-4622EMC Documentum Content Server 权限许可和访问控制漏洞
CVE-2014-4621EMC Documentum Content Server 权限许可和访问控制漏洞
CVE-2012-2956SpiceWorks SQL注入漏洞
CVE-2014-0567Adobe Reader和Acrobat 基于堆的缓冲区溢出漏洞
CVE-2014-0566Adobe Reader和Acrobat 安全漏洞
CVE-2014-0565Adobe Reader和Acrobat 缓冲区溢出漏洞

Showing top 20 of 32 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2012-1507

No comments yet


Leave a comment