CVE-2011-4312

Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) diff viewer or (2) screenshot component.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
reviewboardreview_board
𝑥
≤ 1.5.6
reviewboardreview_board
1.0
reviewboardreview_board
1.0:alpha1
reviewboardreview_board
1.0:alpha2
reviewboardreview_board
1.0:alpha3
reviewboardreview_board
1.0:alpha4
reviewboardreview_board
1.0:beta1
reviewboardreview_board
1.0:beta2
reviewboardreview_board
1.0:rc1
reviewboardreview_board
1.0:rc2
reviewboardreview_board
1.0:rc3
reviewboardreview_board
1.0.1
reviewboardreview_board
1.0.2
reviewboardreview_board
1.0.3
reviewboardreview_board
1.0.4
reviewboardreview_board
1.0.5
reviewboardreview_board
1.0.5.1
reviewboardreview_board
1.0.6
reviewboardreview_board
1.0.7
reviewboardreview_board
1.0.8
reviewboardreview_board
1.0.9
reviewboardreview_board
1.1:alpha1
reviewboardreview_board
1.1:alpha2
reviewboardreview_board
1.5
reviewboardreview_board
1.5:beta1
reviewboardreview_board
1.5:beta2
reviewboardreview_board
1.5:rc1
reviewboardreview_board
1.5:rc2
reviewboardreview_board
1.5.1
reviewboardreview_board
1.5.2
reviewboardreview_board
1.5.3
reviewboardreview_board
1.5.4
reviewboardreview_board
1.5.5
reviewboardreview_board
1.6
reviewboardreview_board
1.6:beta1
reviewboardreview_board
1.6:beta2
reviewboardreview_board
1.6:rc1
reviewboardreview_board
1.6:rc2
reviewboardreview_board
1.6.1
reviewboardreview_board
1.6.2
𝑥
= Vulnerable software versions