CVE-2011-2510

Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link.
References
Link Resource
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631818 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062380.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062389.html
http://secunia.com/advisories/45009 Vendor Advisory
http://secunia.com/advisories/45190 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201301-07.xml
http://www.certa.ssi.gouv.fr/site/CERTA-2011-AVI-366/CERTA-2011-AVI-366.html
http://www.debian.org/security/2011/dsa-2320
http://www.dokuwiki.org/changes
http://www.freelists.org/post/dokuwiki/Hotfix-Release-20110525a-Rincewind Patch
http://www.openwall.com/lists/oss-security/2011/06/28/5 Patch
http://www.openwall.com/lists/oss-security/2011/06/29/13 Patch
http://www.securityfocus.com/bid/48364
https://bugzilla.redhat.com/show_bug.cgi?id=717146 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/68122
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631818 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062380.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062389.html
http://secunia.com/advisories/45009 Vendor Advisory
http://secunia.com/advisories/45190 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201301-07.xml
http://www.certa.ssi.gouv.fr/site/CERTA-2011-AVI-366/CERTA-2011-AVI-366.html
http://www.debian.org/security/2011/dsa-2320
http://www.dokuwiki.org/changes
http://www.freelists.org/post/dokuwiki/Hotfix-Release-20110525a-Rincewind Patch
http://www.openwall.com/lists/oss-security/2011/06/28/5 Patch
http://www.openwall.com/lists/oss-security/2011/06/29/13 Patch
http://www.securityfocus.com/bid/48364
https://bugzilla.redhat.com/show_bug.cgi?id=717146 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/68122
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dokuwiki:dokuwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-07-01:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-07-13:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-09-19:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-09-22:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2006-03-05:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2006-03-09:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2006-11-06:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2007-06-26:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2008-05-05:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2009-02-14b:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2009-12-25c:*:*:*:*:*:*:*

History

21 Nov 2024, 01:28

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631818 - Patch () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631818 - Patch
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062380.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062380.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062389.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062389.html -
References () http://secunia.com/advisories/45009 - Vendor Advisory () http://secunia.com/advisories/45009 - Vendor Advisory
References () http://secunia.com/advisories/45190 - Vendor Advisory () http://secunia.com/advisories/45190 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-201301-07.xml - () http://security.gentoo.org/glsa/glsa-201301-07.xml -
References () http://www.certa.ssi.gouv.fr/site/CERTA-2011-AVI-366/CERTA-2011-AVI-366.html - () http://www.certa.ssi.gouv.fr/site/CERTA-2011-AVI-366/CERTA-2011-AVI-366.html -
References () http://www.debian.org/security/2011/dsa-2320 - () http://www.debian.org/security/2011/dsa-2320 -
References () http://www.dokuwiki.org/changes - () http://www.dokuwiki.org/changes -
References () http://www.freelists.org/post/dokuwiki/Hotfix-Release-20110525a-Rincewind - Patch () http://www.freelists.org/post/dokuwiki/Hotfix-Release-20110525a-Rincewind - Patch
References () http://www.openwall.com/lists/oss-security/2011/06/28/5 - Patch () http://www.openwall.com/lists/oss-security/2011/06/28/5 - Patch
References () http://www.openwall.com/lists/oss-security/2011/06/29/13 - Patch () http://www.openwall.com/lists/oss-security/2011/06/29/13 - Patch
References () http://www.securityfocus.com/bid/48364 - () http://www.securityfocus.com/bid/48364 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=717146 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=717146 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/68122 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/68122 -

Information

Published : 2011-07-14 23:55

Updated : 2024-11-21 01:28


NVD link : CVE-2011-2510

Mitre link : CVE-2011-2510

CVE.ORG link : CVE-2011-2510


JSON object : View

Products Affected

dokuwiki

  • dokuwiki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')