CVE-2012-1217 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.5% (pctl 74)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.5% — more likely to be exploited than 74% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-02-21 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| simhl | sths v2 web portal |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | STHS v2 Web Portal - 'prospects.php?team' SQL Injection | 2012-02-13 |
| exploit-db | STHS v2 Web Portal - 'prospect.php?team' SQL Injection | 2012-02-13 |
| exploit-db | STHS v2 Web Portal - 'team.php?team' SQL Injection | 2012-02-13 |
References
- http://0nto.wordpress.com/2012/02/13/sths-v2-web-portal-2-2-sql-injection-vulnerabilty/
- http://packetstormsecurity.org/files/109665/STHS-v2-Web-Portal-2.2-SQL-Injection.html
- http://www.securityfocus.com/bid/51991
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73154
- http://0nto.wordpress.com/2012/02/13/sths-v2-web-portal-2-2-sql-injection-vulnerabilty/
- http://packetstormsecurity.org/files/109665/STHS-v2-Web-Portal-2.2-SQL-Injection.html
- http://www.securityfocus.com/bid/51991
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73154
→ the Explorer · watch your stack · NVD