CVE-2011-1038: XSS
Published Feb 22, 2011
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in the server in IBM Lotus Sametime 8.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the messageString parameter in a WebMessage action or (2) the PATHINFO.
Affected Software
1 affected component
IBM Lotus Sametime=8.0.1
Event History
Feb 22, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1038?
CVE-2011-1038 has a medium severity rating due to the presence of cross-site scripting vulnerabilities.
2
How do I fix CVE-2011-1038?
To fix CVE-2011-1038, apply the latest patches provided by IBM for Lotus Sametime version 8.0.1.
3
What software is affected by CVE-2011-1038?
CVE-2011-1038 specifically affects IBM Lotus Sametime version 8.0.1.
4
Can CVE-2011-1038 allow remote attacks?
Yes, CVE-2011-1038 allows remote attackers to inject arbitrary web scripts or HTML.
5
What are the attack vectors for CVE-2011-1038?
The attack vectors for CVE-2011-1038 include the messageString parameter in a WebMessage action and the PATH_INFO.