[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-1401Date: (C)2011-04-11   (M)2023-12-22


ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.5
Exploit Score: 6.8
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-44079
SECUNIA-44137
BID-47285
ADV-2011-0907
ADV-2011-1005
DSA-2214
FEDORA-2011-5249
http://ikiwiki.info/security/#index39h2

CPE    174
cpe:/a:ikiwiki:ikiwiki:2.65
cpe:/a:ikiwiki:ikiwiki:2.64
cpe:/a:ikiwiki:ikiwiki:2.63
cpe:/a:ikiwiki:ikiwiki:2.62
...
CWE    1
CWE-79
OVAL    4
oval:org.secpod.oval:def:600229
oval:org.secpod.oval:def:102609
oval:org.secpod.oval:def:103025
oval:org.secpod.oval:def:102598
...

© SecPod Technologies