CVE-2011-2927
published 2014-02-05CVE-2011-2927: A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject…
PriorityP423medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
1.47%
70.9th percentile
A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTML into web pages viewed by other users. The flaw is triggered through vectors related to Search forms, enabling attackers to potentially steal sensitive information or perform actions on behalf of the victim.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | spacewalk | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CVE-2011-2927: A flaw was found in Spacewalk and Red Hat Network Satellite
vendor_redhat·2014-02-05·CVSS 5.4
CVE-2011-2927 [MEDIUM] CWE-79 CVE-2011-2927: A flaw was found in Spacewalk and Red Hat Network Satellite
A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTML into web pages viewed by other users. The flaw is triggered through vectors related to Search forms, enabling attackers to potentially steal sensitive information or perform actions on behalf of the victim.
A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTML into web pages viewed by other users. The flaw is triggered through vectors related to Search forms, enabling attackers to potentially steal sensitive information or perform actions on behalf of the victim.
Mitigation: Mitigati
GHSA
GHSA-2738-x33m-p89q: Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1
ghsa_unreviewed·2022-05-17
CVE-2011-2927 [MEDIUM] CWE-79 GHSA-2738-x33m-p89q: Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allow remote attackers to inject arbitrary web script or HTML via vectors related to Search forms.
No detection rules found.
No public exploits indexed.
http://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://access.redhat.com/security/cve/CVE-2011-2927https://bugzilla.redhat.com/show_bug.cgi?id=730955https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=730955https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html
2014-02-05
Published