← Back

CVE-2011-2191

nvd nist
Published: Oct 7, 2011Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, as demonstrated by a crafted nickname field to vserver/apply.

Affected (137)

Cherokee
Configuration A
137 vulnerable
Vulnerable SoftwareAffected Versions
Cherokee Project
Up to 1.2.98
Version 0.10.0
Version 0.10.1
Version 0.11.0
Version 0.11.1
Version 0.11.2
Version 0.11.3
Version 0.11.4
Version 0.11.5
Version 0.11.6
Version 0.3.0
Version 0.4.0
Version 0.4.10
Version 0.4.11
Version 0.4.12
Version 0.4.13
Version 0.4.14
Version 0.4.15
Version 0.4.16
Version 0.4.17
Version 0.4.18
Version 0.4.19
Version 0.4.1
Version 0.4.20
Version 0.4.21
Version 0.4.22
Version 0.4.23
Version 0.4.24
Version 0.4.25
Version 0.4.26
Version 0.4.27
Version 0.4.28
Version 0.4.29
Version 0.4.2
Version 0.4.30
Version 0.4.3
Version 0.4.4
Version 0.4.5
Version 0.4.6
Version 0.4.7
Version 0.4.8
Version 0.4.9
Version 0.5.0
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.5.4
Version 0.5.5
Version 0.5.6
Version 0.6.0
Version 0.6.1
Version 0.7.0
Version 0.7.1
Version 0.7.2
Version 0.8.0
Version 0.8.1
Version 0.9.0
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9.4
Version 0.98.0
Version 0.98.1
Version 0.99.07
Version 0.99.0
Version 0.99.10
Version 0.99.11
Version 0.99.12
Version 0.99.13
Version 0.99.14
Version 0.99.15
Version 0.99.16
Version 0.99.17
Version 0.99.18
Version 0.99.19
Version 0.99.1
Version 0.99.20
Version 0.99.21
Version 0.99.22
Version 0.99.23
Version 0.99.24
Version 0.99.25
Version 0.99.26
Version 0.99.27
Version 0.99.28
Version 0.99.29
Version 0.99.2
Version 0.99.30
Version 0.99.31
Version 0.99.32
Version 0.99.33
Version 0.99.34
Version 0.99.35
Version 0.99.36
Version 0.99.37
Version 0.99.38
Version 0.99.39
Version 0.99.3
Version 0.99.40
Version 0.99.41
Version 0.99.42
Version 0.99.43
Version 0.99.44
Version 0.99.45
Version 0.99.46
Version 0.99.47
Version 0.99.48
Version 0.99.49
Version 0.99.4
Version 0.99.5
Version 0.99.6
Version 0.99.8
Version 0.99.9
Version 1.0.0
Version 1.0.10
Version 1.0.11
Version 1.0.12
Version 1.0.13
Version 1.0.14
Version 1.0.15
Version 1.0.16
Version 1.0.17
Version 1.0.18
Version 1.0.19
Version 1.0.1
Version 1.0.20
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.0.9
Version 1.2.0
Version 1.2.1
Version 1.2.2

References (20)

Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
ExploitPatch
Source: secalert@redhat.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.