CVE-2011-1158: XSS
Published Apr 11, 2011
·Updated
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via an unexpected URI scheme, as demonstrated by a javascript: URI.
Affected Software
2 affected componentsFixes available
pip/feedparser>=5.0<5.0.1
5.0.1
Mark Pilgrim Feedparser=5.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 11, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 23, 2018
Advisory Published
via GitHub·07:51 PM
Frequently Asked Questions
1
What is the severity of CVE-2011-1158?
The severity of CVE-2011-1158 is rated as medium with a score of 6.1.
2
What type of vulnerability is CVE-2011-1158?
CVE-2011-1158 is a cross-site scripting (XSS) vulnerability.
3
How do I fix CVE-2011-1158?
You can fix CVE-2011-1158 by applying the available patch for feedparser version 5.0.1 or later.
4
What software is affected by CVE-2011-1158?
CVE-2011-1158 affects Universal Feed Parser, also known as feedparser or python-feedparser, version 5.x before 5.0.1.
5
Can CVE-2011-1158 be exploited remotely?
Yes, CVE-2011-1158 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.