First published: Wed Feb 26 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Portal | =4.3.0-cp03 | |
Red Hat JBoss Portal | =5.0.0 | |
Red Hat JBoss Portal | =5.1.0 | |
Red Hat JBoss Portal | =4.3.0-cp06 | |
Red Hat JBoss Portal | =4.3.0-cp07 | |
Red Hat JBoss Portal | =4.3.0 | |
Red Hat JBoss Portal | <=5.1.1 | |
Red Hat JBoss Portal | =4.3.0-cp05 | |
Red Hat JBoss Portal | =5.0.1 | |
Red Hat JBoss Portal | =4.3.0-cp04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4580 has a severity rating that allows remote attackers to exploit cross-site scripting vulnerabilities.
To fix CVE-2011-4580, it is recommended to upgrade to Red Hat JBoss Enterprise Portal Platform version 5.2.0 or later.
CVE-2011-4580 allows attackers to inject arbitrary web scripts or HTML via multiple vectors, leading to potential phishing attacks or session hijacking.
CVE-2011-4580 affects Red Hat JBoss Enterprise Portal Platform versions up to 5.1.1, including multiple versions 4.3.0 and 5.0.0.
CVE-2011-4580 does not specify the exact vectors, indicating multiple unknown entry points for exploitation.