Vulnerability Description
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zope | Zope | >= 2.8.0, < 2.8.12 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2012/01/19/16Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/01/19/17Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/01/19/18Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/01/19/19Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/cve-2011-4924Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924Issue TrackingThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-4924Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/01/19/16Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/01/19/17Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/01/19/18Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/01/19/19Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/cve-2011-4924Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924Issue TrackingThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-4924Third Party Advisory
FAQ
What is CVE-2011-4924?
CVE-2011-4924 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote att...
How severe is CVE-2011-4924?
CVE-2011-4924 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-4924?
Check the references section above for vendor advisories and patch information. Affected products include: Zope Zope.