First published: Wed Jun 15 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the QueryString to the SystemGroupList.do page.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Spacewalk | =1.6 | |
Red Hat Satellite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2919 is classified as a moderate severity cross-site scripting vulnerability.
To fix CVE-2011-2919, update to the fixed versions of Spacewalk or Red Hat Satellite provided by Red Hat.
CVE-2011-2919 allows remote attackers to inject malicious scripts that could lead to unauthorized actions or data theft.
CVE-2011-2919 affects Red Hat Spacewalk version 1.6 and Red Hat Network Satellite.
Yes, CVE-2011-2919 can be exploited by unauthenticated remote attackers via manipulated query strings.