CVE-2011-5303: XSS
Published Jan 1, 2015
·Updated
Cross-site scripting (XSS) vulnerability in Spitfire CMS 1.0.436 allows remote attackers to inject arbitrary web script or HTML via a cmsusername cookie.
Affected Software
1 affected component
Clausmuus Spitfire=1.0436
Event History
Jan 1, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5303?
CVE-2011-5303 is classified as a medium severity vulnerability.
2
How do I fix CVE-2011-5303?
To fix CVE-2011-5303, upgrade Spitfire CMS to a version that no longer includes the vulnerability.
3
What impact does CVE-2011-5303 have on web applications?
CVE-2011-5303 allows attackers to perform cross-site scripting attacks, potentially leading to the theft of sensitive user information.
4
Is CVE-2011-5303 easy to exploit?
CVE-2011-5303 can be easily exploited by an attacker with basic knowledge of web scripting.
5
Which versions of Spitfire CMS are affected by CVE-2011-5303?
CVE-2011-5303 affects Spitfire CMS version 1.0.436.