CVE-2011-2694
published 2011-07-29CVE-2011-2694: Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows…
PriorityP416low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
6.29%
92.9th percentile
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:3.5.10~dfsg-1 (bookworm) | samba 2:3.5.10~dfsg-1 (bookworm) |
| samba | samba | >= 0 < 2:3.5.10~dfsg-1 | 2:3.5.10~dfsg-1 |
| samba | samba | >= 0 < 2:3.5.10~dfsg-1 | 2:3.5.10~dfsg-1 |
| samba | samba | >= 0 < 2:3.5.10~dfsg-1 | 2:3.5.10~dfsg-1 |
| samba | samba | >= 0 < 2:3.5.10~dfsg-1 | 2:3.5.10~dfsg-1 |
| samba | samba | >= 3.0.0 < 3.3.16 | 3.3.16 |
| samba | samba | >= 3.4.0 < 3.4.14 | 3.4.14 |
| samba | samba | >= 3.5.0 < 3.5.10 | 3.5.10 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv2.6LOW
vendor_ubuntu6.8MEDIUM
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9xqr-g3w9-82pj: Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat
ghsa_unreviewed·2022-05-14
CVE-2011-2694 [LOW] CWE-79 GHSA-9xqr-g3w9-82pj: Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
OSV
CVE-2011-2694: Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat
osv·2011-07-29·CVSS 2.6
CVE-2011-2694 [LOW] CVE-2011-2694: Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2011-08-02·CVSS 6.8
CVE-2011-2522 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: An attacker could use a malicious URL to reconfigure Samba or steal
information.
Yoshihiro Ishikawa discovered that the Samba Web Administration Tool (SWAT)
was vulnerable to cross-site request forgeries (CSRF). If a Samba
administrator were tricked into clicking a link on a specially crafted web
page, an attacker could trigger commands that could modify the Samba
configuration. (CVE-2011-2522)
Nobuhiro Tsuji discovered that the Samba Web Administration Tool (SWAT) did
not properly sanitize its input when processing password change requests,
resulting in cross-site scripting (XSS) vulnerabilities. With cross-site
scripting vulnerabilities, if a user were tricked into viewing server
output during a crafted server request, a remote attacker could expl
Red Hat
(SWAT): XSS flaw in Change Password page
vendor_redhat·2011-07-26·CVSS 2.6
CVE-2011-2694 [LOW] CWE-79 (SWAT): XSS flaw in Change Password page
(SWAT): XSS flaw in Change Password page
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
Package: samba4 (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-2694: samba - Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat....
vendor_debian·2011·CVSS 2.6
CVE-2011-2694 [LOW] CVE-2011-2694: samba - Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat....
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
Scope: local
bookworm: resolved (fixed in 2:3.5.10~dfsg-1)
bullseye: resolved (fixed in 2:3.5.10~dfsg-1)
forky: resolved (fixed in 2:3.5.10~dfsg-1)
sid: resolved (fixed in 2:3.5.10~dfsg-1)
trixie: resolved (fixed in 2:3.5.10~dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2522 CVE-2011-2694 samba various flaws [fedora-all]
bugzilla·2011-07-26·CVSS 6.8
CVE-2011-2522 [MEDIUM] CVE-2011-2522 CVE-2011-2694 samba various flaws [fedora-all]
CVE-2011-2522 CVE-2011-2694 samba various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=721348
Please note: this issue affects multiple supported ver
Bugzilla
CVE-2011-2694 samba (SWAT): XSS flaw in Change Password page
bugzilla·2011-07-15·CVSS 2.6
CVE-2011-2694 [LOW] CVE-2011-2694 samba (SWAT): XSS flaw in Change Password page
CVE-2011-2694 samba (SWAT): XSS flaw in Change Password page
It was found that the 'Change Password' page / screen of the Samba Web Administration Tool did not properly sanitize content of the user-provided
"user" field, prior printing it back to the page content. A remote attacker could provide a specially-crafted URL, which once visited by an authenticated Samba SWAT user could allow the attacker to conduct cross-site scripting attacks (execute arbitrary HTML or script code).
Upstream bug report:
[1] https://bugzilla.samba.org/show_bug.cgi?id=8290 (not public yet)
Acknowledgements:
Red Hat would like to thank the Samba project for reporting this issue. Upstream acknowledges Nobuhiro Tsuji of NTT DATA SECURITY CORPORATION as the original reporter.
Discussion:
This issue affects the
http://jvn.jp/en/jp/JVN63041502/index.htmlhttp://osvdb.org/74072http://samba.org/samba/history/samba-3.5.10.htmlhttp://secunia.com/advisories/45393http://secunia.com/advisories/45488http://secunia.com/advisories/45496http://securitytracker.com/id?1025852http://ubuntu.com/usn/usn-1182-1http://www.debian.org/security/2011/dsa-2290http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543http://www.mandriva.com/security/advisories?name=MDVSA-2011:121http://www.samba.org/samba/security/CVE-2011-2694http://www.securityfocus.com/bid/48901https://bugzilla.redhat.com/show_bug.cgi?id=722537https://bugzilla.samba.org/show_bug.cgi?id=8289https://exchange.xforce.ibmcloud.com/vulnerabilities/68844http://jvn.jp/en/jp/JVN63041502/index.htmlhttp://osvdb.org/74072http://samba.org/samba/history/samba-3.5.10.htmlhttp://secunia.com/advisories/45393http://secunia.com/advisories/45488http://secunia.com/advisories/45496http://securitytracker.com/id?1025852http://ubuntu.com/usn/usn-1182-1http://www.debian.org/security/2011/dsa-2290http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543http://www.mandriva.com/security/advisories?name=MDVSA-2011:121http://www.samba.org/samba/security/CVE-2011-2694http://www.securityfocus.com/bid/48901https://bugzilla.redhat.com/show_bug.cgi?id=722537https://bugzilla.samba.org/show_bug.cgi?id=8289https://exchange.xforce.ibmcloud.com/vulnerabilities/68844
2011-07-29
Published