{"api_version":"1","generated_at":"2026-07-23T07:09:10+00:00","cve":"CVE-2011-1030","urls":{"html":"https://cve.report/CVE-2011-1030","api":"https://cve.report/api/cve/CVE-2011-1030.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1030","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1030"},"summary":{"title":"CVE-2011-1030","description":"Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the \"Confirm New Page scene.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2011-02-14 22:00:07","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/43134","name":"http://secunia.com/advisories/43134","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Lotus Connections Wikis Cross-Site Scripting Vulnerability - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ibm.com/support/docview.wss?uid=swg1LO57850","name":"http://www.ibm.com/support/docview.wss?uid=swg1LO57850","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM LO57850: PREVENT XSS ATTACK","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1LO57850","name":"http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1LO57850","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM LO57850: PREVENT XSS ATTACK","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1025054","name":"http://securitytracker.com/id?1025054","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Lotus Connections Input Validation Hole in Wikis Permits Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1030","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1030","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1030","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_connections","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:14:27.163Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1025054","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1025054"},{"name":"43134","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43134"},{"name":"LO57850","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www.ibm.com/support/docview.wss?uid=swg1LO57850"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1LO57850"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the \"Confirm New Page scene.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-02-14T21:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1025054","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1025054"},{"name":"43134","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43134"},{"name":"LO57850","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www.ibm.com/support/docview.wss?uid=swg1LO57850"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1LO57850"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-1030","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the \"Confirm New Page scene.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1025054","refsource":"SECTRACK","url":"http://securitytracker.com/id?1025054"},{"name":"43134","refsource":"SECUNIA","url":"http://secunia.com/advisories/43134"},{"name":"LO57850","refsource":"AIXAPAR","url":"http://www.ibm.com/support/docview.wss?uid=swg1LO57850"},{"name":"http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1LO57850","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1LO57850"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-1030","datePublished":"2011-02-14T21:00:00.000Z","dateReserved":"2011-02-14T00:00:00.000Z","dateUpdated":"2024-09-17T01:21:06.256Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-02-14 22:00:07","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_connections:3.0:*:*:*:*:*:*:*","matchCriteriaId":"215D3AB6-B87F-40FE-8B29-3FF212579238"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1030","Ordinal":"1","Title":"CVE-2011-1030","CVE":"CVE-2011-1030","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1030","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the \"Confirm New Page scene.\"","Type":"Description","Title":"CVE-2011-1030"},{"CveYear":"2011","CveId":"1030","Ordinal":"2","NoteData":"2011-02-14","Type":"Other","Title":"Published"}]}}}