Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2694

Опубликовано: 26 июл. 2011
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6samba4Not affected
Red Hat Enterprise Linux 4sambaFixedRHSA-2011:121929.08.2011
Red Hat Enterprise Linux 5sambaFixedRHSA-2011:121929.08.2011
Red Hat Enterprise Linux 5samba3xFixedRHSA-2011:122029.08.2011
Red Hat Enterprise Linux 6cifs-utilsFixedRHSA-2011:122129.08.2011
Red Hat Enterprise Linux 6sambaFixedRHSA-2011:122129.08.2011

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=722537(SWAT): XSS flaw in Change Password page

EPSS

Процентиль: 87%
0.03385
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).

nvd
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).

debian
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the chg_passwd function in ...

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).

oracle-oval
почти 14 лет назад

ELSA-2011-1220: samba3x security update (MODERATE)

EPSS

Процентиль: 87%
0.03385
Низкий

4.3 Medium

CVSS2