CVE-2012-1261 describes a cross-site scripting (XSS) vulnerability in Plixer International Scrutinizer NetFlow and sFlow Analyzer versions prior to 9.0.1.19899. Specifically, the cgi-bin/scrut_fa_exclusions.cgi script is susceptible to arbitrary web script or HTML injection via the "standalone" parameter. This vulnerability has a CVSS v3.1 score of 6.1 (Medium), indicating it can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to low impact on confidentiality and integrity. The EPSS score is low, suggesting a low probability of exploitation. There is no evidence of active exploitation, and it is not listed in CISA's KEV catalog. While no Metasploit or Nuclei modules exist, an ExploitDB entry (EDB-18750) references multiple vulnerabilities in Scrutinizer, which may include this one. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.6.2.16204CPE matchmatch criteria | cpe:2.3:a:plixer:scrutinizer_netflow_\&_sflow_analyzer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.