CVE-2011-0462

Multiple cross-site scripting (XSS) vulnerabilities in the login page in the webui component in SUSE openSUSE Build Service (OBS) before 2.1.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
novellopensuse_build_service
𝑥
≤ 2.1.5.1
novellopensuse_build_service
1.0
novellopensuse_build_service
1.5
novellopensuse_build_service
1.6
novellopensuse_build_service
1.7
novellopensuse_build_service
1.7.0
novellopensuse_build_service
1.7.2
novellopensuse_build_service
1.7.3
novellopensuse_build_service
1.7.4
novellopensuse_build_service
1.7.5
novellopensuse_build_service
1.7.6
novellopensuse_build_service
1.7.7
novellopensuse_build_service
1.8
novellopensuse_build_service
1.9.90
novellopensuse_build_service
1.9.91
novellopensuse_build_service
1.9.92
novellopensuse_build_service
2.0
novellopensuse_build_service
2.0.0
novellopensuse_build_service
2.0.1
novellopensuse_build_service
2.0.2
novellopensuse_build_service
2.0.3
novellopensuse_build_service
2.0.4
novellopensuse_build_service
2.0.5
novellopensuse_build_service
2.0.6
novellopensuse_build_service
2.0.7
novellopensuse_build_service
2.0.8
novellopensuse_build_service
2.0.16
novellopensuse_build_service
2.0.103
novellopensuse_build_service
2.0.104
novellopensuse_build_service
2.0.106
novellopensuse_build_service
2.1
novellopensuse_build_service
2.1.0
novellopensuse_build_service
2.1.1
novellopensuse_build_service
2.1.2
novellopensuse_build_service
2.1.3
novellopensuse_build_service
2.1.4
novellopensuse_build_service
2.1.5
𝑥
= Vulnerable software versions