CVE-2011-2694

Priority
Description
Cross-site scripting (XSS) vulnerability in the chg_passwd function in
web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before
3.5.10 allows remote authenticated administrators to inject arbitrary web
script or HTML via the username parameter to the passwd program (aka the
user field to the Change Password page).
Assigned-to
mdeslaur
Notes
Package
Source: samba (LP Ubuntu Debian)
Upstream:released (3.5.10)
Patches:
Upstream:http://ftp.samba.org/pub/samba/patches/security/
More Information

Updated: 2020-03-18 22:06:42 UTC (commit 2ea7df7bd1e69e1e489978d2724a936eb3faa1b8)