First published: Wed Nov 09 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Apple WebObjects | =4.0 | |
Apple WebObjects | <=5.2 | |
Apple WebObjects | =5.1 | |
Apple WebObjects | =3.1 | |
Apple WebObjects | =5.0 | |
Apple WebObjects | =4.5 | |
Apple WebObjects | =3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3998 has been classified as a critical vulnerability due to its potential for remote code execution via cross-site scripting.
CVE-2011-3998 affects Apple WebObjects versions 5.2 and earlier, including versions 3.1, 4.0, 4.5, and 5.0.
To remediate CVE-2011-3998, it is recommended to upgrade Apple WebObjects to a version later than 5.2 where the vulnerability has been patched.
CVE-2011-3998 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Yes, if your web application uses the affected versions of Apple WebObjects, it can be exploited due to the XSS vulnerability.