First published: Tue Aug 16 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric ClearSCADA | =2005 | |
Schneider Electric ClearSCADA | =2007 | |
Schneider Electric ClearSCADA | =2009 | |
Schneider-electric Scx 67 | <r4.5 | |
Schneider-electric Scx 68 | <r3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-3144 is considered moderate due to its potential for cross-site scripting attacks.
To fix CVE-2011-3144, upgrade to a version of ClearSCADA or SCX that is patched and not affected by this vulnerability.
CVE-2011-3144 affects ClearSCADA versions 2005, 2007, 2009 and SCX versions below R4.5 and R3.9.
Yes, CVE-2011-3144 can be exploited remotely by attackers through cross-site scripting techniques.
CVE-2011-3144 can facilitate attacks that inject arbitrary web scripts or HTML into affected applications.