CVE-2011-2644: XSS
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2644?
CVE-2011-2644 is classified as a medium-severity vulnerability due to its cross-site scripting (XSS) nature.
How do I fix CVE-2011-2644?
To fix CVE-2011-2644, upgrade Kiwi to version 3.74.2 or later and ensure SUSE Studio is updated to version 1.1.4 or later.
What types of attacks can CVE-2011-2644 facilitate?
CVE-2011-2644 can facilitate cross-site scripting attacks, allowing remote attackers to inject arbitrary web scripts or HTML.
Which software is affected by CVE-2011-2644?
CVE-2011-2644 affects Kiwi versions before 3.74.2 and SUSE Studio Onsite version 1.1.
Are there any known exploits for CVE-2011-2644?
Yes, CVE-2011-2644 has been identified as having potential exploitation vectors related to RPM info display.