First published: Mon Oct 24 2011(Updated: )
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "web form entries."
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
KENT-WEB WEB FORUM | <=5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3984 has a high severity rating due to its potential for remote code execution via cross-site scripting.
To mitigate CVE-2011-3984, upgrade KENT-WEB WEB FORUM to version 5.2 or later which addresses the XSS vulnerability.
CVE-2011-3984 affects KENT-WEB WEB FORUM version 5.1 and earlier.
CVE-2011-3984 is a cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary web script or HTML.
Yes, there are known exploits that leverage the XSS vulnerability in CVE-2011-3984 to execute malicious scripts.