Unknown · Bad Behavior · CVE-2012-4271
**Name of the Vulnerable Software and Affected Versions**
Bad Behavior plugin versions prior to 2.0.47
Bad Behavior plugin versions 2.2.x prior to 2.2.5
**Description**
The issue allows remote attackers to inject arbitrary web script or HTML via certain parameters, including `PATH INFO`, `httpbl key`, `httpbl maxage`, `httpbl threat`, `reverse proxy addresses`, or `reverse proxy header`.
**Recommendations**
For Bad Behavior plugin versions prior to 2.0.47, update to version 2.0.47 or later.
For Bad Behavior plugin versions 2.2.x prior to 2.2.5, update to version 2.2.5 or later.