← Back

CVE-2011-1937

nvd nist
Published: May 31, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier allows local users to inject arbitrary web script or HTML via a chfn command that changes the real (aka Full Name) field, related to useradmin/index.cgi and useradmin/user-lib.pl.

Affected (79)

Products: Webmin: Webmin
1 product
Webmin
Configuration A
79 vulnerable
Vulnerable SoftwareAffected Versions
Webmin
Up to 1.540
Version 0.75
Version 0.76
Version 0.77
Version 0.78
Version 0.79
Version 0.80
Version 0.81
Version 0.82
Version 0.83
Version 0.84
Version 0.85
Version 0.86
Version 0.87
Version 0.88
Version 0.91
Version 0.92
Version 0.93
Version 0.94
Version 0.950
Version 0.960
Version 0.970
Version 0.980
Version 0.990
Version 1.000
Version 1.010
Version 1.020
Version 1.030
Version 1.040
Version 1.050
Version 1.060
Version 1.070
Version 1.080
Version 1.090
Version 1.100
Version 1.110
Version 1.121
Version 1.130
Version 1.140
Version 1.150
Version 1.160
Version 1.170
Version 1.180
Version 1.190
Version 1.200
Version 1.210
Version 1.220
Version 1.230
Version 1.240
Version 1.250
Version 1.260
Version 1.270
Version 1.280
Version 1.290
Version 1.300
Version 1.310
Version 1.320
Version 1.330
Version 1.340
Version 1.350
Version 1.360
Version 1.370
Version 1.380
Version 1.390
Version 1.400
Version 1.410
Version 1.420
Version 1.430
Version 1.440
Version 1.441
Version 1.450
Version 1.460
Version 1.470
Version 1.480
Version 1.490
Version 1.500
Version 1.510
Version 1.520
Version 1.530

References (20)

Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Source: secalert@redhat.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.