CVE-2011-2920
published 2014-02-05CVE-2011-2920: A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web…
PriorityP427medium5.5CVSS 3.1
AVNACLPRLUIRSUCLILAL
EPSS
2.05%
79.0th percentile
A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field. This could lead to the execution of malicious code in a user's web browser, potentially compromising user sessions or disclosing sensitive information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | spacewalk | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pqp9-2cmp-fx98: Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1
ghsa_unreviewed·2022-05-17
CVE-2011-2920 [MEDIUM] CWE-79 GHSA-pqp9-2cmp-fx98: Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allow remote attackers to inject arbitrary web script or HTML via the "Filter by Synopsis" field and other unspecified filter forms.
Red Hat
CVE-2011-2920: A flaw was found in Spacewalk and Red Hat Network Satellite
vendor_redhat·2014-02-05·CVSS 5.5
CVE-2011-2920 [MEDIUM] CWE-79 CVE-2011-2920: A flaw was found in Spacewalk and Red Hat Network Satellite
A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field. This could lead to the execution of malicious code in a user's web browser, potentially compromising user sessions or disclosing sensitive information.
A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field. This could lead to the execution of malicious code in a user's web browser, potentially compromising user sessions or disclosing sensit
No detection rules found.
No public exploits indexed.
http://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://access.redhat.com/security/cve/CVE-2011-2920https://bugzilla.redhat.com/show_bug.cgi?id=681032https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=681032https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html
2014-02-05
Published