Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2694

Опубликовано: 29 июл. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6

Описание

Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).

РелизСтатусПримечание
devel

not-affected

2:3.5.11~dfsg-1ubuntu1
hardy

released

3.0.28a-1ubuntu4.15
lucid

released

2:3.4.7~dfsg-1ubuntu3.7
maverick

released

2:3.5.4~dfsg-1ubuntu8.5
natty

released

2:3.5.8~dfsg-1ubuntu2.3
upstream

released

3.5.10

Показывать по

EPSS

Процентиль: 87%
0.03385
Низкий

2.6 Low

CVSS2

Связанные уязвимости

redhat
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).

nvd
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).

debian
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the chg_passwd function in ...

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).

oracle-oval
почти 14 лет назад

ELSA-2011-1220: samba3x security update (MODERATE)

EPSS

Процентиль: 87%
0.03385
Низкий

2.6 Low

CVSS2