CVE-2011-2711
published 2011-08-03CVE-2011-2711: Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject…
PriorityP413low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.88%
77.3th percentile
Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the filename associated with the rename hint.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lars_hjemli | cgit | <= 0.9.0.2 | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2711 cgit: XSS flaw in rename hint
bugzilla·2011-07-22·CVSS 3.5
CVE-2011-2711 [LOW] CVE-2011-2711 cgit: XSS flaw in rename hint
CVE-2011-2711 cgit: XSS flaw in rename hint
An cross-site scripting (XSS) flaw was found in the way cgit, a fast web interface for Git, processed the file name in the rename hint. A remote attacker, valid CGit user with push access to the repository, could use this flaw to execute arbitrary web script or HTML code via a push commit message, renaming some file to a file with specially-crafted file name.
References:
[1] http://hjemli.net/pipermail/cgit/2011-July/000276.html
Discussion:
This issue affected the versions of the cgit package, as shipped with Fedora release of 14 and 15.
The relevant cgit package updates for Fedora-14 and Fedora-15 has been already scheduled (cgit-0.9.0.2-2.fc14, cgit-0.9.0.2-2.fc15) and once they have passed the required testing phase, they will be pushed t
arXiv
On the Effectiveness of Clone Detection for Detecting IoT-related Vulnerable Clones
arxiv_fulltext·2021-10-20
On the Effectiveness of Clone Detection for Detecting IoT-related Vulnerable Clones
On the Effectiveness of Clone Detection for Detecting IoT-related Vulnerable Clones
Kentaro Ohno,
Norihiro Yoshida,
Wenqing Zhu
and Hiroaki Takada
Nagoya University, Japan
\k_ohno, yoshida, zhuwqing1995, hiro\@ertl.jp
## Abstract
Since IoT systems provide services over the Internet, they must continue to operate safely even if malicious users attack them.
Since the computational resources of edge devices connected to the IoT are limited, lightweight platforms and network protocols are often used.
Lightweight platforms and network protocols are less resistant to attacks, increasing the risk that developers will embed vulnerabilities.
The code clone research community has been developing approaches to fix buggy (e.g., vulnerable) clones simultaneously. However, there has been little rese
http://hjemli.net/git/cgit/commit/?h=stable&id=bebe89d7c11a92bf206bf6e528c51ffa8ecbc0d5http://hjemli.net/pipermail/cgit/2011-July/000276.htmlhttp://secunia.com/advisories/45358http://secunia.com/advisories/45541http://www.openwall.com/lists/oss-security/2011/07/22/2http://www.openwall.com/lists/oss-security/2011/07/22/6http://www.openwall.com/lists/oss-security/2011/07/22/7http://www.openwall.com/lists/oss-security/2011/07/24/3http://www.openwall.com/lists/oss-security/2011/07/24/4http://www.osvdb.org/74050http://www.securityfocus.com/bid/48866https://bugzilla.redhat.com/show_bug.cgi?id=725042https://exchange.xforce.ibmcloud.com/vulnerabilities/68754https://hermes.opensuse.org/messages/10998459http://hjemli.net/git/cgit/commit/?h=stable&id=bebe89d7c11a92bf206bf6e528c51ffa8ecbc0d5http://hjemli.net/pipermail/cgit/2011-July/000276.htmlhttp://secunia.com/advisories/45358http://secunia.com/advisories/45541http://www.openwall.com/lists/oss-security/2011/07/22/2http://www.openwall.com/lists/oss-security/2011/07/22/6http://www.openwall.com/lists/oss-security/2011/07/22/7http://www.openwall.com/lists/oss-security/2011/07/24/3http://www.openwall.com/lists/oss-security/2011/07/24/4http://www.osvdb.org/74050http://www.securityfocus.com/bid/48866https://bugzilla.redhat.com/show_bug.cgi?id=725042https://exchange.xforce.ibmcloud.com/vulnerabilities/68754https://hermes.opensuse.org/messages/10998459
2011-08-03
Published