Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-3606

Опубликовано: 02 дек. 2011
Источник: redhat
CVSS2: 3.5

Описание

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.

Отчет

Not vulnerable. This issue only affects community JBoss AS 7 prior to 7.1.0 Beta 1. It does not affect components shipped with any Red Hat products.

Дополнительная информация

Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=742984AS: DOM based XSS in the administration console

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 6 лет назад

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.

CVSS3: 5.4
nvd
больше 6 лет назад

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.

CVSS3: 5.4
debian
больше 6 лет назад

A DOM based cross-site scripting flaw was found in the JBoss Applicati ...

CVSS3: 5.4
github
больше 4 лет назад

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.

3.5 Low

CVSS2