---
cve: "CVE-2012-3382"
severity: "LOW"
cvss: 3.1
epss: "1.9%"
vendor: "n/a"
kev: false
exploited: false
published: "2012-07-12 21:55:08"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T19:13:02+02:00"
---

# CVE-2012-3382

> 3.1 LOW · 🧪 PoC

## Beschreibung

Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message.

## Referenzen

- <https://github.com/mono/mono/commit/d16d4623edb210635bec3ca3786481b82cde25a2>
- <https://hermes.opensuse.org/messages/15374367>
- <https://bugzilla.novell.com/show_bug.cgi?id=769799>
- <http://www.openwall.com/lists/oss-security/2012/07/06/11>
- <http://www.mandriva.com/security/advisories?name=MDVSA-2012:140>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2012-3382) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
