CVE-2011-1401

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-1401
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2011-1401.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2011-1401
Related
Published
2011-04-11T18:55:03Z
Modified
2024-09-18T01:00:20Z
Summary
[none]
Details

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

References

Affected packages

Debian:11 / ikiwiki

Package

Name
ikiwiki
Purl
pkg:deb/debian/ikiwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20110328

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / ikiwiki

Package

Name
ikiwiki
Purl
pkg:deb/debian/ikiwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20110328

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / ikiwiki

Package

Name
ikiwiki
Purl
pkg:deb/debian/ikiwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20110328

Ecosystem specific

{
    "urgency": "not yet assigned"
}