CVE-2011-3320: XSS
Cross-site scripting (XSS) vulnerability in the Web Administrator component in GE Intelligent Platforms Proficy Historian 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3320?
CVE-2011-3320 is classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2011-3320?
To fix CVE-2011-3320, update the GE Intelligent Platforms Proficy Historian software to version 4.0 or later.
Which versions of GE Intelligent Platforms Proficy Historian are affected by CVE-2011-3320?
CVE-2011-3320 affects versions 3.1, 3.5, and all versions up to and including 4.0 of GE Intelligent Platforms Proficy Historian.
What is cross-site scripting as it relates to CVE-2011-3320?
CVE-2011-3320 allows remote attackers to inject arbitrary web scripts or HTML into web pages served by the affected product.
Can CVE-2011-3320 be exploited remotely?
Yes, CVE-2011-3320 can be exploited remotely by attackers targeting the web interface of the affected software.