VDB

DEBIAN-CVE-2011-2522

DEBIAN-CVE-2011-2522 PUBLISHED CVSS 4.599999904632568 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.

Risk Scores

CVSS v4.0
4.599999904632568
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:11samba0, 0, 0
Debian:12samba0, 0, 0
Debian:14samba0, 0, 0
Debian:13samba0, 0, 0

Timeline

  • Jul 29, 2011 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›