CVE-2011-3344
published 2014-02-05CVE-2011-3344: A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting…
PriorityP422medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
1.47%
70.9th percentile
A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting arbitrary web script or HTML via the URI. This can lead to information disclosure or unauthorized actions within the user's browser session.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | spacewalk | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvhw-hg3x-xxxp: Cross-site scripting (XSS) vulnerability in the Lookup Login/Password form in Spacewalk 1
ghsa_unreviewed·2022-05-17
CVE-2011-3344 [MEDIUM] CWE-79 GHSA-fvhw-hg3x-xxxp: Cross-site scripting (XSS) vulnerability in the Lookup Login/Password form in Spacewalk 1
Cross-site scripting (XSS) vulnerability in the Lookup Login/Password form in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the URI.
Red Hat
CVE-2011-3344: A flaw was found in Spacewalk
vendor_redhat·2014-02-05·CVSS 5.4
CVE-2011-3344 [MEDIUM] CWE-79 CVE-2011-3344: A flaw was found in Spacewalk
A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting arbitrary web script or HTML via the URI. This can lead to information disclosure or unauthorized actions within the user's browser session.
A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting arbitrary web script or HTML via the URI. This can lead to information disclosure or unauthorized actions within the user's browser session.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread
No detection rules found.
http://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://access.redhat.com/security/cve/CVE-2011-3344https://bugzilla.redhat.com/show_bug.cgi?id=731647https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=890781d7ec983e32fe83af2f7c033d087292851fhttps://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=731647https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=890781d7ec983e32fe83af2f7c033d087292851fhttps://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html
2014-02-05
Published