|
|
| |
|
| |
samba: multiple vulnerabilities
| Package(s): | samba |
CVE #(s): | CVE-2011-2522
CVE-2011-2694
|
| Created: | July 27, 2011 |
Updated: | September 23, 2011 |
| Description: |
From the Mandriva advisory:
All current released versions of Samba are vulnerable to a cross-site
request forgery in the Samba Web Administration Tool (SWAT). By
tricking a user who is authenticated with SWAT into clicking a
manipulated URL on a different web page, it is possible to manipulate
SWAT (CVE-2011-2522).
All current released versions of Samba are vulnerable to a cross-site
scripting issue in the Samba Web Administration Tool (SWAT). On the
Change Password field, it is possible to insert arbitrary content
into the user field (CVE-2011-2694).
|
| Alerts: |
|
( Log in to post comments)
|
|
|