Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to SlideShow.pm in the SlideShowPlugin.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-3010
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.mavitunasecurity.com/xss-vulnerability-in-twiki5
- http://www.osvdb.org/75674
- http://securitytracker.com/id?1026091
- http://secunia.com/advisories/46123
- http://develop.twiki.org/trac/changeset/21920
- http://www.securityfocus.com/bid/49746
- http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2011-3010
- http://archives.neohapsis.com/archives/bugtraq/2011-09/0142.html
- http://www.osvdb.org/75673
More from twiki
View All →Affected Vendor
twiki
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.