First published: Tue Jan 03 2012(Updated: )
Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pfSense | <=2.0 | |
pfSense | =1.2.1 | |
pfSense | =1.0.x | |
pfSense | =1.2.2 | |
pfSense | =1.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5047 is classified as a medium severity vulnerability.
To fix CVE-2011-5047, upgrade pfSense to version 2.0.1 or later.
CVE-2011-5047 is a Cross-site Scripting (XSS) vulnerability.
CVE-2011-5047 affects pfSense versions prior to 2.0.1, including 1.0.x, 1.2.1, 1.2.2, and 1.2.3.
Yes, CVE-2011-5047 can allow remote attackers to inject arbitrary web scripts or HTML, potentially leading to site compromise.