Vulnerability Description
Cross-site scripting (XSS) vulnerability in Namazu before 2.0.21, when Internet Explorer 6 or 7 is used, allows remote attackers to inject arbitrary web script or HTML via a cookie.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Namazu | Namazu | <= 2.0.20 |
| Microsoft | Internet Explorer | 6 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/46925Vendor Advisory
- http://www.namazu.org/security.html#cross-site-scriptingVendor Advisory
- http://www.securityfocus.com/bid/50771
- https://bugzilla.redhat.com/show_bug.cgi?id=756348
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c
- http://secunia.com/advisories/46925Vendor Advisory
- http://www.namazu.org/security.html#cross-site-scriptingVendor Advisory
- http://www.securityfocus.com/bid/50771
- https://bugzilla.redhat.com/show_bug.cgi?id=756348
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c
FAQ
What is CVE-2011-4345?
CVE-2011-4345 is a vulnerability with a CVSS score of 2.6 (LOW). Cross-site scripting (XSS) vulnerability in Namazu before 2.0.21, when Internet Explorer 6 or 7 is used, allows remote attackers to inject arbitrary web script or HTML via a cookie.
How severe is CVE-2011-4345?
CVE-2011-4345 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-4345?
Check the references section above for vendor advisories and patch information. Affected products include: Namazu Namazu, Microsoft Internet Explorer.