PT-2012-1248 · Jquery+2 · Jquery+2

Timmywil

·

Published

2012-02-06

·

Updated

2026-02-18

·

CVE-2012-6708

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions jquery versions prior to 1.9.0
Description The issue is related to the jQuery function not properly differentiating between HTML and selectors, allowing for cross-site scripting attacks. In vulnerable versions, jQuery determines whether the input is HTML by looking for the '<' character anywhere in the string, giving attackers flexibility when constructing a malicious payload. This can lead to client-side code execution. The estimated number of potentially affected devices is not specified.
Recommendations Update to version 1.9.0 or later. As a temporary workaround, consider restricting the use of the vulnerable jquery function until a patch is available. Avoid using the jquery function with untrusted input to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

AZL-40951
AZL-43897
AZL-44730
AZL-44937
BDU:2023-07702
CVE-2012-6708
GHSA-2PQJ-H3VJ-PQGW
OPENSUSE-SU-2020:0395-1
OPENSUSE-SU-2020_0395-1
SUSE-SU-2020:0737-1
USN-7622-1

Affected Products

Suse
Ubuntu
Jquery