{"api_version":"1","generated_at":"2026-07-23T06:31:37+00:00","cve":"CVE-2011-1668","urls":{"html":"https://cve.report/CVE-2011-1668","api":"https://cve.report/api/cve/CVE-2011-1668.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1668","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1668"},"summary":{"title":"CVE-2011-1668","description":"Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-04-10 02:51:20","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/47126","name":"http://www.securityfocus.com/bid/47126","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/517294/100/0/threaded","name":"http://www.securityfocus.com/archive/1/517294/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/8193","name":"http://securityreason.com/securityalert/8193","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secpod.org/advisories/SECPOD_AWCM_XSS.txt","name":"http://secpod.org/advisories/SECPOD_AWCM_XSS.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66536","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66536","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1668","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1668","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1668","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"awcm-cms","cpe5":"ar_web_content_manager","cpe6":"2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1668","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"awcm-cms","cpe5":"ar_web_content_manager","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:37:25.009Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secpod.org/advisories/SECPOD_AWCM_XSS.txt"},{"name":"arwebcontentmanager-search-xss(66536)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66536"},{"name":"47126","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/47126"},{"name":"8193","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/8193"},{"name":"20110401 AR Web Content Manager (AWCM) Cross-Site scripting Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/517294/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-04-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://secpod.org/advisories/SECPOD_AWCM_XSS.txt"},{"name":"arwebcontentmanager-search-xss(66536)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66536"},{"name":"47126","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/47126"},{"name":"8193","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/8193"},{"name":"20110401 AR Web Content Manager (AWCM) Cross-Site scripting Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/517294/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-1668","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://secpod.org/advisories/SECPOD_AWCM_XSS.txt","refsource":"MISC","url":"http://secpod.org/advisories/SECPOD_AWCM_XSS.txt"},{"name":"arwebcontentmanager-search-xss(66536)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66536"},{"name":"47126","refsource":"BID","url":"http://www.securityfocus.com/bid/47126"},{"name":"8193","refsource":"SREASON","url":"http://securityreason.com/securityalert/8193"},{"name":"20110401 AR Web Content Manager (AWCM) Cross-Site scripting Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/517294/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-1668","datePublished":"2011-04-10T01:00:00.000Z","dateReserved":"2011-04-09T00:00:00.000Z","dateUpdated":"2024-08-06T22:37:25.009Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-04-10 02:51:20","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:awcm-cms:ar_web_content_manager:2.1:*:*:*:*:*:*:*","matchCriteriaId":"7F973228-062F-4015-8F76-2926F51CA9D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:awcm-cms:ar_web_content_manager:2.2:*:*:*:*:*:*:*","matchCriteriaId":"DBC1DF46-22B3-4924-A1C4-D95F9524A16C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1668","Ordinal":"1","Title":"CVE-2011-1668","CVE":"CVE-2011-1668","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1668","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search parameter.","Type":"Description","Title":"CVE-2011-1668"},{"CveYear":"2011","CveId":"1668","Ordinal":"2","NoteData":"2011-04-09","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"1668","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}