CVE-2011-0533: XSS
Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to the autoIncludeParameters setting for the extremecomponents table.
Other sources
Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.22 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to the autoIncludeParameters setting for the extremecomponents table.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0533?
CVE-2011-0533 has been classified as a moderate severity vulnerability due to its potential for Cross-site scripting (XSS) attacks.
How do I fix CVE-2011-0533?
To fix CVE-2011-0533, upgrade to Apache Continuum 1.4.0 Beta or Archiva 1.3.4 or later versions.
What are the affected versions for CVE-2011-0533?
CVE-2011-0533 affects Apache Continuum versions 1.1 to 1.4.0 Beta and Archiva versions 1.0 to 1.3.3.
Can CVE-2011-0533 be exploited remotely?
Yes, CVE-2011-0533 can be exploited remotely by attackers injecting arbitrary web scripts or HTML.
What type of vulnerability is CVE-2011-0533?
CVE-2011-0533 is a Cross-site scripting (XSS) vulnerability.