Unrated severityNVD Advisory· Published Aug 28, 2012· Updated Apr 29, 2026
CVE-2012-4685
CVE-2012-4685
Description
Cross-site scripting (XSS) vulnerability in Arbor Networks Peakflow SP 5.1.1 before patch 6, 5.5 before patch 4, and 5.6.0 before patch 1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.
Affected products
3cpe:2.3:a:arbornetworks:peakflow_sp:5.1.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:arbornetworks:peakflow_sp:5.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:arbornetworks:peakflow_sp:5.5:*:*:*:*:*:*:*
- cpe:2.3:a:arbornetworks:peakflow_sp:5.6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/bid/52881nvdExploit
- secunia.com/advisories/48728nvdVendor Advisory
- archives.neohapsis.com/archives/bugtraq/2012-04/0019.htmlnvd
- archives.neohapsis.com/archives/bugtraq/2012-04/0036.htmlnvd
- archives.neohapsis.com/archives/bugtraq/2012-04/0037.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/74648nvd
News mentions
0No linked articles in our index yet.