CVE-2012-1247
Estado: ModificadaBaja (2.6)—
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML by leveraging support for Cascading Style Sheets (CSS) expressions.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.76%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- http://jvn.jp/en/jp/JVN63941302/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2012-000042
- http://www.kent-web.com/cart/mart.html
- http://www.securityfocus.com/bid/53541
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75674
- http://jvn.jp/en/jp/JVN63941302/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2012-000042
- http://www.kent-web.com/cart/mart.html
- http://www.securityfocus.com/bid/53541
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75674
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-1247",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-05-15T20:55:01.777",
"references": [
{
"url": "http://jvn.jp/en/jp/JVN63941302/index.html",
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2012-000042",
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://www.kent-web.com/cart/mart.html",
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://www.securityfocus.com/bid/53541",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75674",
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://jvn.jp/en/jp/JVN63941302/index.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2012-000042",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kent-web.com/cart/mart.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/53541",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75674",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML by leveraging support for Cascading Style Sheets (CSS) expressions."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en KENT-WEB WEB MART v1.7 y anteriores, cuando Internet Explorer es usado, permiten a atacantes remotos inyectar secuencias de comandos web o HTML aprovechándose de expresiones \"Cascading Style Sheets\" (CSS)"
}
],
"lastModified": "2026-06-16T23:39:18.930",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webcreate:web_mart:1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57A246DF-CF35-44F0-987E-52A0D97FA555"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}