CVE-2011-5025: XSS
Published Dec 29, 2011
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.
Affected Software
1 affected component
Yaws yaws=1.88
Event History
Dec 29, 2011
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5025?
The severity of CVE-2011-5025 is considered moderate due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2011-5025?
To fix CVE-2011-5025, upgrade to Yaws version 1.89 or later.
3
What types of vulnerabilities are present in CVE-2011-5025?
CVE-2011-5025 contains multiple cross-site scripting (XSS) vulnerabilities in the Yaws wiki application.
4
Which versions of Yaws are affected by CVE-2011-5025?
Yaws version 1.88 is affected by CVE-2011-5025.
5
Can CVE-2011-5025 allow remote attackers to execute scripts?
Yes, CVE-2011-5025 allows remote attackers to inject arbitrary web scripts or HTML.