Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-3606

Опубликовано: 26 нояб. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5
CVSS3: 5.4

Описание

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.

РелизСтатусПримечание
devel

not-affected

4.2.3.GA-6
hardy

not-affected

lucid

not-affected

maverick

not-affected

natty

not-affected

oneiric

not-affected

upstream

not-affected

Показывать по

Ссылки на источники

EPSS

Процентиль: 60%
0.00402
Низкий

3.5 Low

CVSS2

5.4 Medium

CVSS3

Связанные уязвимости

redhat
около 14 лет назад

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.

CVSS3: 5.4
nvd
около 6 лет назад

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.

CVSS3: 5.4
debian
около 6 лет назад

A DOM based cross-site scripting flaw was found in the JBoss Applicati ...

CVSS3: 5.4
github
почти 4 года назад

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.

EPSS

Процентиль: 60%
0.00402
Низкий

3.5 Low

CVSS2

5.4 Medium

CVSS3