CVE-2011-4615
published 2011-12-29CVE-2011-4615: Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.37%
69.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:1.8.10-1 (bookworm) | zabbix 1:1.8.10-1 (bookworm) |
| zabbix | zabbix | <= 1.8.10 | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f832-gjrw-m8w5: Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1
ghsa_unreviewed·2022-05-17
CVE-2011-4615 [MEDIUM] CWE-79 GHSA-f832-gjrw-m8w5: Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1
Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php.
OSV
CVE-2011-4615: Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1
osv·2011-12-29·CVSS 4.3
CVE-2011-4615 [MEDIUM] CVE-2011-4615: Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1
Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php.
Debian
CVE-2011-4615: zabbix - Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allo...
vendor_debian·2011·CVSS 4.3
CVE-2011-4615 [MEDIUM] CVE-2011-4615: zabbix - Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allo...
Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php.
Scope: local
bookworm: resolved (fixed in 1:1.8.10-1)
bullseye: resolved (fixed in 1:1.8.10-1)
forky: resolved (fixed in 1:1.8.10-1)
sid: resolved (fixed in 1:1.8.10-1)
trixie: resolved (fixed in 1:1.8.10-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4615 zabbix: persistent XSS flaws in 1.8.x
bugzilla·2011-12-16·CVSS 4.3
CVE-2011-4615 [MEDIUM] CVE-2011-4615 zabbix: persistent XSS flaws in 1.8.x
CVE-2011-4615 zabbix: persistent XSS flaws in 1.8.x
Zabbix 1.8.10rc1 was released [1] to correct persistant cross-site scripting vulnerabilities due to improper sanitization of the gname variable when creating user and host groups [2].
[1] http://www.zabbix.com/rn1.8.10rc1.php
[2] https://support.zabbix.com/browse/ZBX-4015
Discussion:
CVE requested:
http://www.openwall.com/lists/oss-security/2011/12/16/2
---
This was assigned the name CVE-2011-4615:
http://www.openwall.com/lists/oss-security/2011/12/16/3
---
Created zabbix tracking bugs for this issue
Affects: fedora-all [bug 768539]
Affects: epel-6 [bug 768540]
---
zabbix-1.8.10-1.fc15 has been pushed to the Fedora 15 stable repository. If problems still persist, please make note of it in this bug report.
---
zabbix-1.8.10-
Bugzilla
CVE-2011-4615 zabbix: persistent XSS flaws in 1.8.x [fedora-all]
bugzilla·2011-12-16·CVSS 4.3
CVE-2011-4615 [MEDIUM] CVE-2011-4615 zabbix: persistent XSS flaws in 1.8.x [fedora-all]
CVE-2011-4615 zabbix: persistent XSS flaws in 1.8.x [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=76852
Bugzilla
CVE-2011-4615 zabbix: persistent XSS flaws in 1.8.x [epel-6]
bugzilla·2011-12-16·CVSS 4.3
CVE-2011-4615 [MEDIUM] CVE-2011-4615 zabbix: persistent XSS flaws in 1.8.x [epel-6]
CVE-2011-4615 zabbix: persistent XSS flaws in 1.8.x [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=768525
e
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071660.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-January/071687.htmlhttp://osvdb.org/77771http://secunia.com/advisories/47216http://www.securityfocus.com/bid/51093http://www.zabbix.com/rn1.8.10.phphttps://exchange.xforce.ibmcloud.com/vulnerabilities/71855https://support.zabbix.com/browse/ZBX-4015http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071660.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-January/071687.htmlhttp://osvdb.org/77771http://secunia.com/advisories/47216http://www.securityfocus.com/bid/51093http://www.zabbix.com/rn1.8.10.phphttps://exchange.xforce.ibmcloud.com/vulnerabilities/71855https://support.zabbix.com/browse/ZBX-4015
2011-12-29
Published