Medium severity6.1NVD Advisory· Published Jan 3, 2020· Updated Jun 16, 2026
CVE-2012-4451
CVE-2012-4451
Description
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- Range: 2.0.x before 2.0.1
Patches
Vulnerability mechanics
References
8- seclists.org/oss-sec/2012/q3/571nvdMailing ListPatchThird Party Advisory
- seclists.org/oss-sec/2012/q3/573nvdMailing ListPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- github.com/zendframework/zf2/commit/27131ca9520bdf1d4c774c71459eba32f2b10733nvdPatchThird Party Advisory
- framework.zend.com/security/advisory/ZF2012-03nvdVendor Advisory
- www.securityfocus.com/bid/55636nvdThird Party AdvisoryVDB Entry
- bugs.debian.org/cgi-bin/bugreport.cginvdMailing ListThird Party Advisory
- bugs.gentoo.org/show_bug.cginvdThird Party Advisory
News mentions
0No linked articles in our index yet.