Vulnerability Database

290,273

Total vulnerabilities in the database

CVE-2011-2711

Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the filename associated with the rename hint.

  • Published: Aug 3, 2011
  • Updated: Apr 13, 2023
  • CVE: CVE-2011-2711
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:N/I:P/A:N
Software From Fixed in
lars_hjemli / cgit 0.7.1 0.7.1.x
lars_hjemli / cgit 0.8.3.1 0.8.3.1.x
lars_hjemli / cgit 0.9 0.9.x
lars_hjemli / cgit 0.6.1 0.6.1.x
lars_hjemli / cgit 0.6 0.6.x
lars_hjemli / cgit 0.8 0.8.x
lars_hjemli / cgit 0.3 0.3.x
lars_hjemli / cgit 0.5 0.5.x
lars_hjemli / cgit 0.8.1.1 0.8.1.1.x
lars_hjemli / cgit 0.8.3.4 0.8.3.4.x
lars_hjemli / cgit 0.2 0.2.x
lars_hjemli / cgit 0.8.3.2 0.8.3.2.x
lars_hjemli / cgit 0.8.3 0.8.3.x
lars_hjemli / cgit 0.1 0.1.x
lars_hjemli / cgit - 0.9.0.2.x
lars_hjemli / cgit 0.6.2 0.6.2.x
lars_hjemli / cgit 0.8.3.5 0.8.3.5.x
lars_hjemli / cgit 0.8.2.2 0.8.2.2.x
lars_hjemli / cgit 0.7.2 0.7.2.x
lars_hjemli / cgit 0.4 0.4.x
lars_hjemli / cgit 0.8.2 0.8.2.x
lars_hjemli / cgit 0.8.1 0.8.1.x
lars_hjemli / cgit 0.9.0.1 0.9.0.1.x
lars_hjemli / cgit 0.8.3.3 0.8.3.3.x
lars_hjemli / cgit 0.8.2.1 0.8.2.1.x
lars_hjemli / cgit 0.7 0.7.x
lars_hjemli / cgit 0.6.3 0.6.3.x