{"api_version":"1","generated_at":"2026-07-23T04:31:28+00:00","cve":"CVE-2011-3978","urls":{"html":"https://cve.report/CVE-2011-3978","api":"https://cve.report/api/cve/CVE-2011-3978.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-3978","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-3978"},"summary":{"title":"CVE-2011-3978","description":"Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment action for the news page.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-10-04 10:55:11","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69737","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69737","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/519571/100/0/threaded","name":"http://www.securityfocus.com/archive/1/519571/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/8407","name":"http://securityreason.com/securityalert/8407","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"LightNEasy 3.2.4 Multiple XSS vulnerabilities - SecurityReason.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.lightneasy.org/punbb/viewtopic.php?id=1464","name":"http://www.lightneasy.org/punbb/viewtopic.php?id=1464","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"LightNEasy Support Forum / Multiple XSS vulnerabilities in LightNEasy 3.2.4","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.rul3z.de/advisories/SSCHADV2011-013.txt","name":"http://www.rul3z.de/advisories/SSCHADV2011-013.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"AfterMarket.pl :: domena rul3z.de","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://osvdb.org/75262","name":"http://osvdb.org/75262","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/45955","name":"http://secunia.com/advisories/45955","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"LightNEasy Multiple Script Insertion Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-3978","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-3978","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"3978","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lightneasy","cpe5":"lightneasy","cpe6":"3.2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T23:53:32.548Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20110908 Multiple XSS vulnerabilities in LightNEasy 3.2.4","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/519571/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.rul3z.de/advisories/SSCHADV2011-013.txt"},{"name":"8407","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/8407"},{"name":"45955","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/45955"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.lightneasy.org/punbb/viewtopic.php?id=1464"},{"name":"75262","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/75262"},{"name":"lightneasy-lightneasy-multiple-xss(69737)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69737"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-09-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment action for the news page."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20110908 Multiple XSS vulnerabilities in LightNEasy 3.2.4","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/519571/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://www.rul3z.de/advisories/SSCHADV2011-013.txt"},{"name":"8407","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/8407"},{"name":"45955","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/45955"},{"tags":["x_refsource_MISC"],"url":"http://www.lightneasy.org/punbb/viewtopic.php?id=1464"},{"name":"75262","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/75262"},{"name":"lightneasy-lightneasy-multiple-xss(69737)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69737"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-3978","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment action for the news page."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20110908 Multiple XSS vulnerabilities in LightNEasy 3.2.4","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/519571/100/0/threaded"},{"name":"http://www.rul3z.de/advisories/SSCHADV2011-013.txt","refsource":"MISC","url":"http://www.rul3z.de/advisories/SSCHADV2011-013.txt"},{"name":"8407","refsource":"SREASON","url":"http://securityreason.com/securityalert/8407"},{"name":"45955","refsource":"SECUNIA","url":"http://secunia.com/advisories/45955"},{"name":"http://www.lightneasy.org/punbb/viewtopic.php?id=1464","refsource":"MISC","url":"http://www.lightneasy.org/punbb/viewtopic.php?id=1464"},{"name":"75262","refsource":"OSVDB","url":"http://osvdb.org/75262"},{"name":"lightneasy-lightneasy-multiple-xss(69737)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69737"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-3978","datePublished":"2011-10-04T10:00:00.000Z","dateReserved":"2011-10-03T00:00:00.000Z","dateUpdated":"2024-08-06T23:53:32.548Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-10-04 10:55:11","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:lightneasy:lightneasy:3.2.4:*:*:*:*:*:*:*","matchCriteriaId":"9D5DC63C-3A99-4A62-B6D3-6E9955DBC736"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"3978","Ordinal":"1","Title":"CVE-2011-3978","CVE":"CVE-2011-3978","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"3978","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment action for the news page.","Type":"Description","Title":"CVE-2011-3978"},{"CveYear":"2011","CveId":"3978","Ordinal":"2","NoteData":"2011-10-04","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"3978","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}