CVE-2011-2694
Summary
| CVE | CVE-2011-2694 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-07-29 20:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page). |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 722537 – CVE-2011-2694 samba (SWAT): XSS flaw in Change Password page | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch |
| SecurityTracker: Samba Web Administration Tool (SWAT) Input Validation Flaws Permit Cross-Site Request Forgery and Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Vendor Advisory |
| Samba SWAT 'user' Field Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| osvdb.org/74072 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Ubuntu update for samba - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Third Party Advisory |
| mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | Vendor Advisory |
| USN-1182-1: Samba vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | Third Party Advisory |
| Samba - Release Notes Archive | af854a3a-2127-422b-91ae-364da2661108 | samba.org | Vendor Advisory |
| Debian -- Security Information -- DSA-2290-1 samba | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| Bug 8289 – Swat contains a cross-site scripting vulnerability; CVE-2011-2694 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.samba.org | Issue Tracking, Patch |
| JVN#63041502: Samba Web Administration Tool vulnerable to cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | Third Party Advisory |
| Debian update for samba - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Third Party Advisory |
| www.itrc.hp.com/service/cki/docDisplay.do | af854a3a-2127-422b-91ae-364da2661108 | www.itrc.hp.com | Broken Link, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.