CVE-2011-3206
Last modified
CVE-2011-3206 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.. EPSS estimates a 1.15% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Operations Network | <= 2.4.1 |
| Redhat | Jboss Operations Network | 2.0.0 |
| Redhat | Jboss Operations Network | 2.0.1 |
| Redhat | Jboss Operations Network | 2.1.0 |
| Redhat | Jboss Operations Network | 2.2 |
| Redhat | Jboss Operations Network | 2.3 |
| Redhat | Jboss Operations Network | 2.3.1 |
| Redhat | Jboss Operations Network | 2.4 |
| Rhq-Project | Rhq | 4.2.0 |
References
- http://secunia.com/advisories/47197Vendor Advisory
- http://secunia.com/advisories/47280Vendor Advisory
- http://secunia.com/advisories/47197Vendor Advisory
- http://secunia.com/advisories/47280Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-3206?
How severe is CVE-2011-3206?
How do I fix CVE-2011-3206?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-3200Stack-based buffer overflow in the parseLegacySyslogMsg func…
- CVE-2011-3201GNOME Evolution before 3.2.3 allows user-assisted remote att…
- CVE-2011-3202A Cross-Site Scripting (XSS) vulnerability exists in the g p…6.1
- CVE-2011-3203A Code Execution vulnerability exists the attachment paramet…9.8
- CVE-2011-3204hammerhead.cc in Hammerhead 2.1.4 allows local users to writ…
- CVE-2011-3205Buffer overflow in the gopherToHTML function in gopher.cc in…
- CVE-2011-3207crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does n…
- CVE-2011-3208Stack-based buffer overflow in the split_wildmats function i…
- CVE-2011-3209The div_long_long_rem implementation in include/asm-x86/div6…
- CVE-2011-3210The ephemeral ECDH ciphersuite functionality in OpenSSL 0.9.…
- CVE-2011-3211The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, a…
- CVE-2011-3212CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not en…
Are you affected by CVE-2011-3206?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
