First published: Fri Oct 28 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified documentation files in (1) manual/ibm/ and (2) htdocs/*/manual/ibm/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM HTTP Server | <=2.0.47 | |
IBM HTTP Server | =1.3.19 | |
IBM HTTP Server | =1.3.12.2 | |
IBM HTTP Server | =1.3.28 | |
IBM HTTP Server | =2.0.42.1 | |
IBM HTTP Server | =1.3.19.4 | |
IBM HTTP Server | =1.0 | |
IBM HTTP Server | =2.0.42 | |
IBM HTTP Server | =1.3.19.5 | |
IBM HTTP Server | =2.0 | |
IBM HTTP Server | =1.3.12 | |
IBM HTTP Server | =1.3.19.6 | |
IBM HTTP Server | =1.3.28.1 | |
IBM HTTP Server | =1.3.26.1 | |
IBM HTTP Server | =2.0.42.2 | |
IBM HTTP Server | =1.3.6.3 | |
IBM HTTP Server | =1.3.12.7 | |
IBM HTTP Server | =1.3.26 | |
IBM HTTP Server | =1.3.12.6 | |
IBM HTTP Server | =1.3.26.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1360 is classified with a medium severity due to its potential to allow cross-site scripting attacks.
To fix CVE-2011-1360, upgrade to a version of IBM HTTP Server that is higher than 2.0.47.
CVE-2011-1360 affects IBM HTTP Server versions 2.0.47 and earlier, and various versions from the 1.x series.
CVE-2011-1360 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2011-1360 can be exploited by remote attackers to inject arbitrary web scripts or HTML.