{"api_version":"1","generated_at":"2026-07-23T06:31:43+00:00","cve":"CVE-2011-2522","urls":{"html":"https://cve.report/CVE-2011-2522","api":"https://cve.report/api/cve/CVE-2011-2522.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-2522","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-2522"},"summary":{"title":"CVE-2011-2522","description":"Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.","state":"PUBLISHED","assigner":"redhat","published_at":"2011-07-29 20:55:02","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-352","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/48899","name":"http://www.securityfocus.com/bid/48899","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Samba SWAT Cross Site Request Forgery Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1025852","name":"http://securitytracker.com/id?1025852","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityTracker: Samba Web Administration Tool (SWAT) Input Validation Flaws Permit Cross-Site Request Forgery and Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68843","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68843","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/45393","name":"http://secunia.com/advisories/45393","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/8317","name":"http://securityreason.com/securityalert/8317","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Samba Web Administration Tool Cross-Site Request Forgery +PoC  - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.samba.org/samba/security/CVE-2011-2522","name":"http://www.samba.org/samba/security/CVE-2011-2522","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Samba - Security Announcement Archive","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/en/jp/JVN29529126/index.html","name":"http://jvn.jp/en/jp/JVN29529126/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"JVN#29529126: Samba Web Administration Tool vulnerable to cross-site request forgery","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/45496","name":"http://secunia.com/advisories/45496","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Ubuntu update for samba - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:121","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:121","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"mandriva.com","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://ubuntu.com/usn/usn-1182-1","name":"http://ubuntu.com/usn/usn-1182-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-1182-1: Samba vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/17577","name":"http://www.exploit-db.com/exploits/17577","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"SWAT Samba Web Administration Tool Cross-Site Request Forgery PoC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.samba.org/show_bug.cgi?id=8290","name":"https://bugzilla.samba.org/show_bug.cgi?id=8290","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Bug 8290 – CSRF vulnerability in SWAT; CVE-2011-2522","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/74071","name":"http://osvdb.org/74071","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://samba.org/samba/history/samba-3.5.10.html","name":"http://samba.org/samba/history/samba-3.5.10.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Samba - Release Notes Archive","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2011/dsa-2290","name":"http://www.debian.org/security/2011/dsa-2290","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-2290-1 samba","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=721348","name":"https://bugzilla.redhat.com/show_bug.cgi?id=721348","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Bug 721348 – CVE-2011-2522 samba (SWAT): Absent CSRF protection in various Samba web configuration formulars","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=133527864025056&w=2","name":"http://marc.info/?l=bugtraq&m=133527864025056&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"'[security bulletin] HPSBUX02768 SSRT100664 rev.1 - CIFS Server (Samba), Remote Cross Site Request Fo' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/45488","name":"http://secunia.com/advisories/45488","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian update for samba - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543","name":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-2522","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-2522","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"2522","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samba","cpe5":"samba","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T23:00:34.288Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"MDVSA-2011:121","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:121"},{"name":"74071","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/74071"},{"name":"HPSBNS02701","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"},{"name":"SSRT100664","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=133527864025056&w=2"},{"name":"HPSBUX02768","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=133527864025056&w=2"},{"name":"1025852","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1025852"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.samba.org/show_bug.cgi?id=8290"},{"name":"DSA-2290","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2011/dsa-2290"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.samba.org/samba/security/CVE-2011-2522"},{"name":"45393","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/45393"},{"name":"45496","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/45496"},{"name":"45488","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/45488"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=721348"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://samba.org/samba/history/samba-3.5.10.html"},{"name":"SSRT100598","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"},{"name":"17577","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/17577"},{"name":"8317","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/8317"},{"name":"JVN#29529126","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN29529126/index.html"},{"name":"USN-1182-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://ubuntu.com/usn/usn-1182-1"},{"name":"48899","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/48899"},{"name":"samba-swat-csrf(68843)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68843"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-07-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-12T17:57:02.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"MDVSA-2011:121","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:121"},{"name":"74071","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/74071"},{"name":"HPSBNS02701","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"},{"name":"SSRT100664","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=133527864025056&w=2"},{"name":"HPSBUX02768","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=133527864025056&w=2"},{"name":"1025852","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1025852"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.samba.org/show_bug.cgi?id=8290"},{"name":"DSA-2290","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2011/dsa-2290"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.samba.org/samba/security/CVE-2011-2522"},{"name":"45393","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/45393"},{"name":"45496","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/45496"},{"name":"45488","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/45488"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=721348"},{"tags":["x_refsource_CONFIRM"],"url":"http://samba.org/samba/history/samba-3.5.10.html"},{"name":"SSRT100598","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"},{"name":"17577","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/17577"},{"name":"8317","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/8317"},{"name":"JVN#29529126","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN29529126/index.html"},{"name":"USN-1182-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://ubuntu.com/usn/usn-1182-1"},{"name":"48899","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/48899"},{"name":"samba-swat-csrf(68843)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68843"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2011-2522","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"MDVSA-2011:121","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:121"},{"name":"74071","refsource":"OSVDB","url":"http://osvdb.org/74071"},{"name":"HPSBNS02701","refsource":"HP","url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"},{"name":"SSRT100664","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=133527864025056&w=2"},{"name":"HPSBUX02768","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=133527864025056&w=2"},{"name":"1025852","refsource":"SECTRACK","url":"http://securitytracker.com/id?1025852"},{"name":"https://bugzilla.samba.org/show_bug.cgi?id=8290","refsource":"CONFIRM","url":"https://bugzilla.samba.org/show_bug.cgi?id=8290"},{"name":"DSA-2290","refsource":"DEBIAN","url":"http://www.debian.org/security/2011/dsa-2290"},{"name":"http://www.samba.org/samba/security/CVE-2011-2522","refsource":"CONFIRM","url":"http://www.samba.org/samba/security/CVE-2011-2522"},{"name":"45393","refsource":"SECUNIA","url":"http://secunia.com/advisories/45393"},{"name":"45496","refsource":"SECUNIA","url":"http://secunia.com/advisories/45496"},{"name":"45488","refsource":"SECUNIA","url":"http://secunia.com/advisories/45488"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=721348","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=721348"},{"name":"http://samba.org/samba/history/samba-3.5.10.html","refsource":"CONFIRM","url":"http://samba.org/samba/history/samba-3.5.10.html"},{"name":"SSRT100598","refsource":"HP","url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"},{"name":"17577","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/17577"},{"name":"8317","refsource":"SREASON","url":"http://securityreason.com/securityalert/8317"},{"name":"JVN#29529126","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN29529126/index.html"},{"name":"USN-1182-1","refsource":"UBUNTU","url":"http://ubuntu.com/usn/usn-1182-1"},{"name":"48899","refsource":"BID","url":"http://www.securityfocus.com/bid/48899"},{"name":"samba-swat-csrf(68843)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68843"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2011-2522","datePublished":"2011-07-29T20:00:00.000Z","dateReserved":"2011-06-15T00:00:00.000Z","dateUpdated":"2024-08-06T23:00:34.288Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-07-29 20:55:02","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-352","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndExcluding":"3.3.16","matchCriteriaId":"3A7FE6F3-F8CF-46C6-94B8-2717A3BBA803"},{"vulnerable":true,"criteria":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4.0","versionEndExcluding":"3.4.14","matchCriteriaId":"5559D1ED-F753-4842-9F4A-F78C54817835"},{"vulnerable":true,"criteria":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.0","versionEndExcluding":"3.5.10","matchCriteriaId":"7738DB4A-F424-481F-93C0-4C1DEBABAABD"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*","matchCriteriaId":"8C757774-08E7-40AA-B532-6F705C8F7639"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*","matchCriteriaId":"036E8A89-7A16-411F-9D31-676313BB7244"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"16F59A04-14CF-49E2-9973-645477EA09DA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*","matchCriteriaId":"7EBFE35C-E243-43D1-883D-4398D71763CC"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*","matchCriteriaId":"01EDA41C-6B2E-49AF-B503-EB3882265C11"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*","matchCriteriaId":"87614B58-24AB-49FB-9C84-E8DDBA16353B"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*","matchCriteriaId":"EF49D26F-142E-468B-87C1-BABEA445255C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"2522","Ordinal":"1","Title":"CVE-2011-2522","CVE":"CVE-2011-2522","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"2522","Ordinal":"1","NoteData":"Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.","Type":"Description","Title":"CVE-2011-2522"},{"CveYear":"2011","CveId":"2522","Ordinal":"2","NoteData":"2011-07-29","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"2522","Ordinal":"3","NoteData":"2017-12-12","Type":"Other","Title":"Modified"}]}}}