{
    "id": "CVE-2012-4344",
    "published": "2012-08-15 22:55:02",
    "last_modified": "2026-06-16 23:44:51",
    "cvss_score": "4.3",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
    "cwe": "CWE-79",
    "description": "Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the SNMP system name of the attacking host.",
    "epss_score": "0.03811",
    "epss_percentile": "0.89720",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-04 18:17:09",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "progress",
            "product": "whatsup_gold"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "20035",
            "title": "ipswitch whatsup gold 15.02 - Persistent Cross-Site Scripting / Blind SQL Injection / Remote Code Execution",
            "date": "2012-07-22",
            "url": "https://www.exploit-db.com/exploits/20035"
        }
    ],
    "refs_list": [
        "http://www.exploit-db.com/exploits/20035",
        "http://www.kb.cert.org/vuls/id/777007",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/77150",
        "http://www.exploit-db.com/exploits/20035",
        "http://www.kb.cert.org/vuls/id/777007",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/77150"
    ]
}