CVE-2012-3869

Publication date

2012-08-13 20:00:00

Family

mitre

State

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in include/classes/class.rex_list.inc.php in REDAXO 4.3.x and 4.4 allows remote attackers to inject arbitrary web script or HTML via the subpage parameter to index.php.