CVE-2011-5258
Published Feb 12, 2013
Last updated 6 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitrary web script or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php; or the (3) PATH_INFO to lib/controllers/centralcontroller.php.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "738368B2-0357-4B67-B41D-4C6803C88BD4", "versionEndIncluding": "2.6.11" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C84E2EE7-DB15-4887-936E-9424EE323ED5" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF1DF5EE-4211-41AE-B257-464907CD7FE6" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "327D764E-698B-49D7-B69C-35EDACD7C40C" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57014EF9-7825-42D1-BED6-0D81637F42EE" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8075BA4-3AC7-478B-BE42-677A53D3B18B" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DEA34F8A-904D-449A-8607-EDCBE4A13193" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2EEEF1C2-4763-4FE7-9B1F-7AB303DDEEC7" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D5BEFA03-1CC8-4515-82F7-B9505D217468" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30778A4C-28E0-4AD3-B5DC-846D65E96737" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "209887E6-63DC-4802-BC0F-7061514A5E61" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E75B0E7A-F722-46BD-B714-61C9205CE351" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1BC60A9-ECED-4417-A7B8-7198C9AEB02E" }, { "criteria": "cpe:2.3:a:orangehrm:orangehrm:2.6.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D722B5C-9BEE-483A-BC70-CA88319ACDFC" } ], "operator": "OR" } ] } ]