VDB
CVE-2011-3010
CVE-2011-3010
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to SlideShow.pm in the SlideShowPlugin.
EPSS 17.12% · 95.1th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
17.12%
95.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| twiki | twiki | 4.1.1, 0, 4.0 |
| n/a | n/a | n/a |
Timeline
- Sep 30, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- http://www.mavitunasecurity.com/xss-vulnerability-in-twiki5 url
- 75674 vdb
- 1026091 vdb
- 46123 third-party-advisory
- http://develop.twiki.org/trac/changeset/21920 url
- 49746 vdb
- http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2011-3010 url
- 20110922 XSS Vulnerabilities in TWiki < 5.1.0 mailing-list
- 75673 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2011-3010 advisory