jQuery UI – CVE-2012-6662

Description

Kayran has detected that the version of jQuery UI being used is vulnerable to Cross-site scripting (XSS).
This can be done by abusing the jquery.ui.tooltip.js. Also known as CVE-2012-6662.

By abusing the jquery.ui.tooltip.js in the Tooltip widget in jQuery UI, remote attackers can inject arbitrary web scripts or any HTML.
This is done via the title attribute, which is not properly handled in the autocomplete combo box demo.

Severity/Score

CVSS Version 2.0 – 4.3 Medium

Recommendation

To fix CVE-2012-6662, update the version of the jQuery UI being used.
Make sure its version is 1.10.0 or higher.

References

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6662

https://cwe.mitre.org/data/definitions/79.html

< Return to all Vulnerabilities

Using VPN

What is a VPN? Why should someone be using VPN? Which Problems does is solve? and what is the advantages and disadvantages of it? Let’s

Read More »

HAR Files

In this article, I’ll talk and explain about HAR Files, so if you don’t know what they are, or, what do we use them for,

Read More »

The Dark Web

Let’s talk about the darker and more mysterious side of the internet, also known as The Dark Web. You’ve probably heard about it, whether it’s

Read More »

Man-In-The-Middle Attacks

Do you know these people who just push themselves into conversations?That’s Man-In-The-Middle Attacks. And from a wider angle, Man-In-The-Middle Attacks, or MITM, are built around

Read More »