← Back

CVE-2011-1401

nvd nist
Published: Apr 11, 2011Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

Affected (174)

Products: Ikiwiki: Ikiwiki
1 product
Ikiwiki
Configuration A
174 vulnerable
Vulnerable SoftwareAffected Versions
Ikiwiki
Up to 3.20110321
Version 1.0
Version 1.1.47
Version 1.10
Version 1.11
Version 1.12
Version 1.13
Version 1.14
Version 1.15
Version 1.16
Version 1.17
Version 1.18
Version 1.19
Version 1.1
Version 1.20
Version 1.21
Version 1.22
Version 1.23
Version 1.24
Version 1.25
Version 1.26
Version 1.27
Version 1.28
Version 1.29
Version 1.2
Version 1.30
Version 1.31
Version 1.32
Version 1.33.3
Version 1.34.1
Version 1.34.2
Version 1.34
Version 1.35
Version 1.36
Version 1.37
Version 1.38
Version 1.39
Version 1.3
Version 1.40
Version 1.41
Version 1.42
Version 1.43
Version 1.44
Version 1.45
Version 1.46
Version 1.47
Version 1.48
Version 1.49
Version 1.4
Version 1.50
Version 1.51
Version 1.5
Version 1.6
Version 1.7
Version 1.8
Version 1.9
Version 2.00
Version 2.0
Version 2.10
Version 2.11
Version 2.12
Version 2.13
Version 2.14
Version 2.15
Version 2.16
Version 2.17
Version 2.18
Version 2.19
Version 2.1
Version 2.20
Version 2.2
Version 2.30
Version 2.31.1
Version 2.31.2
Version 2.31.3
Version 2.31
Version 2.3
Version 2.40
Version 2.41
Version 2.42
Version 2.43
Version 2.44
Version 2.45
Version 2.46
Version 2.47
Version 2.48
Version 2.49
Version 2.4
Version 2.50
Version 2.51
Version 2.52
Version 2.53
Version 2.54
Version 2.55
Version 2.56
Version 2.5
Version 2.6.1
Version 2.60
Version 2.61
Version 2.62.1
Version 2.62
Version 2.63
Version 2.64
Version 2.65
Version 2.66
Version 2.67
Version 2.68
Version 2.69
Version 2.6
Version 2.70
Version 2.71
Version 2.72
Version 2.7
Version 2.8
Version 2.9
Version 3.00
Version 3.01
Version 3.02
Version 3.03
Version 3.04
Version 3.05
Version 3.06
Version 3.07
Version 3.08
Version 3.09
Version 3.0
Version 3.10
Version 3.11
Version 3.12
Version 3.13
Version 3.14159265
Version 3.1415926
Version 3.141592
Version 3.14159
Version 3.1415
Version 3.141
Version 3.14
Version 3.20091009
Version 3.20091017
Version 3.20091022
Version 3.20091023
Version 3.20091031
Version 3.20091113
Version 3.20091202
Version 3.20091218
Version 3.20100102.3
Version 3.20100122
Version 3.20100212
Version 3.20100302
Version 3.20100312
Version 3.20100403
Version 3.20100427
Version 3.20100501
Version 3.20100504
Version 3.20100515
Version 3.20100518.2
Version 3.20100518
Version 3.20100610
Version 3.20100623
Version 3.20100722
Version 3.20100804
Version 3.20100815
Version 3.20100831
Version 3.20100926
Version 3.20101019
Version 3.20101023
Version 3.20101112
Version 3.20101129
Version 3.20101201
Version 3.20101231
Version 3.20110105
Version 3.20110123
Version 3.20110124
Version 3.20110225

References (16)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.