CVE-2011-3423
Summary
| CVE | CVE-2011-3423 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-09-19 12:02:00 UTC |
| Updated | 2017-08-29 01:30:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Managed File Transfer server in TIBCO Managed File Transfer Internet Server before 7.1.1 and Managed File Transfer Command Center before 7.1.1, and the server in TIBCO Slingshot before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker: TIBCO Slingshot Bugs Permit Cross-Site Scripting and Session Hijacking Attacks | SECTRACK | securitytracker.com | |
| 75396 | OSVDB | www.osvdb.org | |
| TIBCO | TIBCO® Managed File Transfer Internet Server, TIBCO® Managed File Transfer Command Center, TIBCO® Slingshot | CONFIRM | www.tibco.com | |
| 404 Not Found | CONFIRM | www.tibco.com | |
| TIBCO Managed File Transfer Products Session Fixation and Cross Site Scripting Vulnerabilities | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| TIBCO Managed File Transfer Products Cross-Site Scripting and Session Fixation Vulnerabilities - Secunia.com | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.