Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.
References 5 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 5 Total
- securityfocus.com: 49236 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: kiwi-rpm-xss(69279) vdb-entryx_transferred
- lists.opensuse.org: SUSE-SU-2011:0917 vendor-advisoryx_transferred
- http://support.novell.com/security/cve/CVE-2011-2644.html x_transferred
- https://bugzilla.novell.com/show_bug.cgi?id=700591 x_transferred