4.3

CVE-2011-2224

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NovellData Synchronizer Version1.0.0
NovellData Synchronizer Version1.1.0
NovellData Synchronizer Version1.1.1
NovellData Synchronizer Version1.1.2
NovellMobility Pack Version <= 1.1.2
NovellMobility Pack Version1.0
NovellMobility Pack Version1.1
NovellMobility Pack Version1.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.721
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.