CVE-2011-3606
Summary
| CVE | CVE-2011-3606 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-26 02:15:00 UTC |
| Updated | 2023-02-13 01:21:00 UTC |
| Description | A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Application Server | 7.0.0 | All | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | alpha1 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | beta1 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | beta2 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | beta3 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | cr1 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.1 | All | All | All |
| Application | Redhat | Jboss Application Server | 7.0.2 | All | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | All | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | alpha1 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | beta1 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | beta2 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | beta3 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.0 | cr1 | All | All |
| Application | Redhat | Jboss Application Server | 7.0.1 | All | All | All |
| Application | Redhat | Jboss Application Server | 7.0.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 742984 – CVE-2011-3606 JBoss AS: DOM based XSS in the administration console | MISC | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| access.redhat.com/security/cve/CVE-2011-3606 | MISC | access.redhat.com | |
| CVE-2011-3606 - Red Hat Customer Portal | MISC | access.redhat.com | Third Party Advisory |
| Bug 742984 – CVE-2011-3606 JBoss AS: DOM based XSS in the administration console | MISC | bugzilla.redhat.com | |
| CVE-2011-3606 | MISC | security-tracker.debian.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.