CVE-2011-3206
published 2012-01-08CVE-2011-3206: Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON)…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.15%
63.3th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_operations_network | <= 2.4.1 | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| rhq-project | rhq | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3j98-rrxh-qmw6: Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4
ghsa_unreviewed·2022-05-17
CVE-2011-3206 [MEDIUM] CWE-79 GHSA-3j98-rrxh-qmw6: Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Red Hat
JON: Multiple XSS flaws
vendor_redhat·2011-12-08·CVSS 4.3
CVE-2011-3206 [MEDIUM] CWE-79 JON: Multiple XSS flaws
JON: Multiple XSS flaws
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-0089.htmlhttp://secunia.com/advisories/47197http://secunia.com/advisories/47280http://securitytracker.com/id?1026435https://bugzilla.redhat.com/show_bug.cgi?id=734662http://rhn.redhat.com/errata/RHSA-2012-0089.htmlhttp://secunia.com/advisories/47197http://secunia.com/advisories/47280http://securitytracker.com/id?1026435https://bugzilla.redhat.com/show_bug.cgi?id=734662
2012-01-08
Published