CVE-2011-0462: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the login page in the webui component in SUSE openSUSE Build Service (OBS) before 2.1.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0462?
CVE-2011-0462 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2011-0462?
To fix CVE-2011-0462, upgrade to SUSE openSUSE Build Service version 2.1.6 or later.
What types of attacks are possible with CVE-2011-0462?
CVE-2011-0462 allows remote attackers to perform cross-site scripting attacks that can lead to information theft or session hijacking.
What components are affected by CVE-2011-0462?
CVE-2011-0462 affects the webui component of SUSE openSUSE Build Service.
Which versions of openSUSE Build Service are vulnerable to CVE-2011-0462?
Versions of SUSE openSUSE Build Service prior to 2.1.6, including 1.0 to 2.1.5.1, are vulnerable to CVE-2011-0462.