← Back

CVE-2011-4035

nvd nist
Published: Dec 2, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected (8)

Vijeo Historian
Citecthistorian
Citectscada Reports
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.30
Version 4.0
Version 4.10
Version 4.20
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.30
Version 4.20
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.10
Version 4.0

Timeline

No history available yet.