CVE-2011-4273: XSS
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the url parameter to goform/AddAccessLimit, related to addlimit.asp; or the (3) user (aka User ID) or (4) group parameter to goform/AddUser, related to adduser.asp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4273?
CVE-2011-4273 is categorized as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-4273?
To fix CVE-2011-4273, users should upgrade to a later version of the GoAhead Webserver that does not contain the vulnerability.
Which versions of GoAhead Webserver are affected by CVE-2011-4273?
CVE-2011-4273 affects GoAhead Webserver version 2.1.8.
What types of attacks does CVE-2011-4273 allow?
CVE-2011-4273 allows remote attackers to perform cross-site scripting (XSS) attacks which can inject arbitrary web scripts or HTML.
Where can I find more details about CVE-2011-4273?
Details about CVE-2011-4273 can be found in security advisories and vulnerability databases.