CVE-2012-5851 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 2.29% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-11-15 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| apple | safari |
| apple | webkit |
| chrome |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WebKit Cross-Site Scripting Filter - 'Cross-Site ScriptingAuditor.cpp' Security Bypass | 2012-07-19 |
References
- http://blog.opensecurityresearch.com/2012/09/simple-cross-site-scripting-vector-that.html
- https://bugs.webkit.org/show_bug.cgi?id=92692
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80072
- http://blog.opensecurityresearch.com/2012/09/simple-cross-site-scripting-vector-that.html
- https://bugs.webkit.org/show_bug.cgi?id=92692
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80072
→ the Explorer · watch your stack · NVD