CVE-2011-0533
CVE-2011-0533
Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.22 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to the autoIncludeParameters setting for the extremecomponents table.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://continuum.apache.org/security.htmlhttp://jira.codehaus.org/browse/CONTINUUM-2604http://mail-archives.apache.org/mod_mbox/continuum-users/201102.mbox/%3C981C0A79-5B7B-4053-84CC-3217870BE360%40apache.org%3Ehttp://osvdb.org/70925http://seclists.org/fulldisclosure/2011/Feb/236http://secunia.com/advisories/43261http://secunia.com/advisories/43334http://securityreason.com/securityalert/8091http://securitytracker.com/id?1025065https://exchange.xforce.ibmcloud.com/vulnerabilities/65343https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12581http://svn.apache.org/viewvc?view=revision&revision=1066053