CVE-2011-4642
Summary
| CVE | CVE-2011-4642 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-01-03 11:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators to execute arbitrary code by leveraging the sys module in a request to the search application, as demonstrated by a cross-site request forgery (CSRF) attack, aka SPL-45172. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Splunk 4.2.5 addresses three vulnerabilities - December 12th, 2011 | Splunk | af854a3a-2127-422b-91ae-364da2661108 | www.splunk.com | Vendor Advisory |
| Advisory: Multiple Splunk Vulnerabilities | Sec-1 Labs | af854a3a-2127-422b-91ae-364da2661108 | www.sec-1.com | Exploit |
| Sec-1 now fully incorporated into Claranet. How to find us. | Claranet UK | af854a3a-2127-422b-91ae-364da2661108 | www.sec-1.com | Exploit |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Splunk Bugs Permit Remote Autheticated Code Injection and Directory Traversal and Remote Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Splunk Remote Root Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.