Lucene search

K
cveMitreCVE-2011-4273
HistoryNov 03, 2011 - 10:55 a.m.

CVE-2011-4273

2011-11-0310:55:08
CWE-79
mitre
web.nvd.nist.gov
27
cve
2011
4273
xss
vulnerabilities
goahead
webserver

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.003

Percentile

70.6%

Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the url parameter to goform/AddAccessLimit, related to addlimit.asp; or the (3) user (aka User ID) or (4) group parameter to goform/AddUser, related to adduser.asp.

Affected configurations

Nvd
Node
goaheadgoahead_webserverMatch2.1.8
VendorProductVersionCPE
goaheadgoahead_webserver2.1.8cpe:2.3:a:goahead:goahead_webserver:2.1.8:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.003

Percentile

70.6%