CVE-2011-5047: XSS
Published Jan 3, 2012
·Updated
Cross-site scripting (XSS) vulnerability in statusrrdgraph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.
Affected Software
5 affected components
pfSense pfSense<=2.0
pfSense pfSense=1.2.1
pfSense pfSense=1.0.x
pfSense pfSense=1.2.2
pfSense pfSense=1.2.3
Event History
Jan 3, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5047?
CVE-2011-5047 is classified as a medium severity vulnerability.
2
How do I fix CVE-2011-5047?
To fix CVE-2011-5047, upgrade pfSense to version 2.0.1 or later.
3
What type of vulnerability is CVE-2011-5047?
CVE-2011-5047 is a Cross-site Scripting (XSS) vulnerability.
4
Which versions of pfSense are affected by CVE-2011-5047?
CVE-2011-5047 affects pfSense versions prior to 2.0.1, including 1.0.x, 1.2.1, 1.2.2, and 1.2.3.
5
Can CVE-2011-5047 lead to site compromise?
Yes, CVE-2011-5047 can allow remote attackers to inject arbitrary web scripts or HTML, potentially leading to site compromise.