Sploitus

CVE-2011-2191

No indexed exploits for CVE-2011-2191 yet

Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, as demonstrated by a crafted nickname field to vserver/apply.

Affected products
Cherokee
Cherokee-project Cherokee
≤ 1.2.98, 0.3.0, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.4.6, 0.4.7, 0.4.8, 0.4.9, 0.4.10, 0.4.11, 0.4.12, 0.4.13, 0.4.14, 0.4.15, 0.4.16, 0.4.17, 0.4.18, 0.4.19, 0.4.20, 0.4.21, 0.4.22, 0.4.23, 0.4.24, 0.4.25, 0.4.26, 0.4.27, 0.4.28, 0.4.29, 0.4.30, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
1.4% (70th percentile)
Weakness
CWE-352
NVD status
Modified
Published
2011-10-07
CVE-2011-2191 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2011-2191 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2011-2191 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.