Lucene search

K
cveMitreCVE-2011-5301
HistoryJan 01, 2015 - 11:59 a.m.

CVE-2011-5301

2015-01-0111:59:07
CWE-79
mitre
web.nvd.nist.gov
26
cve
2011
5301
xss
vulnerabilities
phpdug
remote
attackers
web script
html
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

50.3%

Multiple cross-site scripting (XSS) vulnerabilities in PHPDug 2.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the story_url parameter to add_story.php, (2) the email parameter to editprofile.php, (3) the title parameter to adm/content_add.php, or (4) the username parameter to adm/admin_edit.php.

Affected configurations

Nvd
Node
kubelabsphpdugMatch2.0.0
VendorProductVersionCPE
kubelabsphpdug2.0.0cpe:2.3:a:kubelabs:phpdug:2.0.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

50.3%

Related for CVE-2011-5301