Candidate: CVE-2011-1723 PublicDate: 2011-04-19 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1723 Description: Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_redmine: upstream_redmine: released (1.1.2-2) dapper_redmine: DNE hardy_redmine: DNE karmic_redmine: DNE lucid_redmine: ignored (reached end-of-life) maverick_redmine: ignored (reached end-of-life) natty_redmine: ignored (reached end-of-life) oneiric_redmine: ignored (reached end-of-life) precise_redmine: ignored (reached end-of-life) precise/esm_redmine: DNE (precise was needs-triage) quantal_redmine: ignored (reached end-of-life) raring_redmine: ignored (reached end-of-life) saucy_redmine: ignored (reached end-of-life) trusty_redmine: not-affected (2.4.2-1) trusty/esm_redmine: DNE (trusty was not-affected [2.4.2-1]) utopic_redmine: ignored (reached end-of-life) vivid_redmine: ignored (reached end-of-life) vivid/stable-phone-overlay_redmine: DNE vivid/ubuntu-core_redmine: DNE wily_redmine: ignored (reached end-of-life) xenial_redmine: not-affected (2.4.2-1) yakkety_redmine: ignored (reached end-of-life) zesty_redmine: ignored (reached end-of-life) artful_redmine: not-affected (2.4.2-1) bionic_redmine: not-affected (2.4.2-1) devel_redmine: not-affected (2.4.2-1)