Lucene search

K
cveMitreCVE-2011-1129
HistoryJun 21, 2011 - 2:52 a.m.

CVE-2011-1129

2011-06-2102:52:42
CWE-79
mitre
web.nvd.nist.gov
27
cve-2011-1129
cross-site scripting
xss
smf
vulnerability
web script
html
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

41.8%

Cross-site scripting (XSS) vulnerability in the EditNews function in ManageNews.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, might allow remote authenticated users to inject arbitrary web script or HTML via a save_items action.

Affected configurations

Nvd
Node
simplemachinessmfRange1.1.12
OR
simplemachinessmfMatch1.0
OR
simplemachinessmfMatch1.0beta4
OR
simplemachinessmfMatch1.0beta4.1
OR
simplemachinessmfMatch1.0beta5
OR
simplemachinessmfMatch1.0beta6
OR
simplemachinessmfMatch1.0rc1
OR
simplemachinessmfMatch1.0rc2
OR
simplemachinessmfMatch1.0.1
OR
simplemachinessmfMatch1.0.2
OR
simplemachinessmfMatch1.0.3
OR
simplemachinessmfMatch1.0.4
OR
simplemachinessmfMatch1.0.5
OR
simplemachinessmfMatch1.0.6
OR
simplemachinessmfMatch1.0.7
OR
simplemachinessmfMatch1.0.8
OR
simplemachinessmfMatch1.0.9
OR
simplemachinessmfMatch1.0.10
OR
simplemachinessmfMatch1.0.12
OR
simplemachinessmfMatch1.0.13
OR
simplemachinessmfMatch1.0.14
OR
simplemachinessmfMatch1.0.15
OR
simplemachinessmfMatch1.0.16
OR
simplemachinessmfMatch1.0.17
OR
simplemachinessmfMatch1.0.18
OR
simplemachinessmfMatch1.0.19
OR
simplemachinessmfMatch1.0.20
OR
simplemachinessmfMatch1.0.21
OR
simplemachinessmfMatch1.1
OR
simplemachinessmfMatch1.1beta1
OR
simplemachinessmfMatch1.1beta2
OR
simplemachinessmfMatch1.1beta3
OR
simplemachinessmfMatch1.1beta4
OR
simplemachinessmfMatch1.1rc1
OR
simplemachinessmfMatch1.1rc2
OR
simplemachinessmfMatch1.1rc3
OR
simplemachinessmfMatch1.1.1
OR
simplemachinessmfMatch1.1.2
OR
simplemachinessmfMatch1.1.3
OR
simplemachinessmfMatch1.1.4
OR
simplemachinessmfMatch1.1.5
OR
simplemachinessmfMatch1.1.6
OR
simplemachinessmfMatch1.1.7
OR
simplemachinessmfMatch1.1.8
OR
simplemachinessmfMatch1.1.9
OR
simplemachinessmfMatch1.1.10
OR
simplemachinessmfMatch1.1.11
Node
simplemachinessmfMatch2.0beta1
OR
simplemachinessmfMatch2.0beta2
OR
simplemachinessmfMatch2.0beta2.1
OR
simplemachinessmfMatch2.0beta3
OR
simplemachinessmfMatch2.0beta3.1
OR
simplemachinessmfMatch2.0beta4
OR
simplemachinessmfMatch2.0rc1
OR
simplemachinessmfMatch2.0rc2
OR
simplemachinessmfMatch2.0rc3
OR
simplemachinessmfMatch2.0rc4
VendorProductVersionCPE
simplemachinessmf*cpe:2.3:a:simplemachines:smf:*:*:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:*:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:beta4:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:beta4.1:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:beta5:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:beta6:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:rc1:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:rc2:*:*:*:*:*:*
simplemachinessmf1.0.1cpe:2.3:a:simplemachines:smf:1.0.1:*:*:*:*:*:*:*
simplemachinessmf1.0.2cpe:2.3:a:simplemachines:smf:1.0.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 571

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

41.8%

Related for CVE-2011-1129