First published: Tue Aug 23 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Marcus Schafer Kiwi | <=3.74.1 | |
Novell Suse Studio Onsite | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2226 is classified as a medium severity vulnerability due to its ability to allow remote attackers to execute arbitrary web scripts.
To fix CVE-2011-2226, upgrade to Kiwi version 3.74.2 or later, and SUSE Studio version 1.1.4 or later.
CVE-2011-2226 is a cross-site scripting (XSS) vulnerability.
CVE-2011-2226 affects Kiwi versions prior to 3.74.2 and SUSE Studio version 1.1.
Yes, remote attackers can exploit CVE-2011-2226 to inject arbitrary web scripts.