CVE-2011-5149
SpamTitan 5.08 - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.08 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) testaddr or (2) testpass parameter to auth-settings.php; (3) hostname, (4) domainname, or (5) mailserver parameter to setup-relay.php; or (6) subnetmask or (7) defaultroute parameter to setup-network.php.
Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en SpamTitan v5.08 y anteriores permite a atacantes remotos o usuarios autenticados inyectar secuencias de comandos web o HTML a través de los parámetros (1) testaddr or (2) testpass de setup-network.phpauth-settings.php; los parámetros (3) hostname, (4) domainname, o (5) mailserver de setup-relay.php; o los parámetros (6) subnetmask o (7) defaultroute de setup-network.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-21 First Exploit
- 2012-08-31 CVE Reserved
- 2012-08-31 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/77987 | Vdb Entry | |
http://osvdb.org/77988 | Vdb Entry | |
http://osvdb.org/77989 | Vdb Entry | |
http://www.vulnerability-lab.com/get_content.php?id=91 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/71942 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/18261 | 2011-12-21 | |
http://www.exploit-db.com/exploits/18261 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/47309 | 2017-08-29 |