Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to <script> tags in a rendered response.
References
Link Resource
http://www.securityfocus.com/bid/101644 Third Party Advisory VDB Entry
https://wicket.apache.org/news/2013/03/03/cve-2012-5636.html Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2017-10-30T19:00:00

Updated: 2017-11-03T09:57:01

Reserved: 2012-10-24T00:00:00


Link: CVE-2012-5636

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-10-30T19:29:00.247

Modified: 2017-11-18T16:08:36.783


Link: CVE-2012-5636

JSON object: View

cve-icon Redhat Information

No data.

CWE