CVE-2011-4969
Summary
| CVE | CVE-2011-4969 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-03-08 22:55:00 UTC |
| Updated | 2023-11-07 02:09:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| jQuery 'location.hash' Cross Site Scripting Vulnerability | BID | www.securityfocus.com | |
| Pony Mail! | lists.apache.org | ||
| oss-security - jQuery 1.6.2 XSS CVE assignment | MLIST | www.openwall.com | |
| #9521 (XSS with $(location.hash) and $(#<tag>) is needed?) – jQuery Core - Bug Tracker | CONFIRM | bugs.jquery.com | |
| jQuery: » jQuery 1.6.3 Released | CONFIRM | blog.jquery.com | |
| 80056 | OSVDB | www.osvdb.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Minded Security Blog: jQuery is a Sink! | MISC | blog.mindedsecurity.com | |
| USN-1722-1: jQuery vulnerability | Ubuntu | UBUNTU | www.ubuntu.com | |
| HPE integrated Lights Out (iLO) Input Validation Flaw in JQuery Lets Remote Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Document Display | HPE Support Center | CONFIRM | h20566.www2.hpe.com | |
| Document Display | HPE Support Center | CONFIRM | h20566.www2.hpe.com | |
| Merge pull request #474 from dmethvin/fix-9521-xss-hash · db9e023 · jquery/jquery · GitHub | CONFIRM | github.com | Exploit, Patch |
| September 2018 jQuery Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Document Display | HPE Support Center | CONFIRM | h20566.www2.hpe.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.