CVE-2011-4969 - Medium Severity Vulnerability
Vulnerable Libraries - jquery-1.4.2.min.js, jquery-1.4.4.js
jquery-1.4.2.min.js
JavaScript library for DOM operations
path: /muzich/web/js/jConfirmAction/jquery-1.4.2.min.js
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jquery/1.4.2/jquery.min.js
Dependency Hierarchy:
- ❌ jquery-1.4.2.min.js (Vulnerable Library)
jquery-1.4.4.js
JavaScript library for DOM operations
path: /muzich/web/bundles/sonatajquery/jquery-1.4.4.js
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jquery/1.4.4/jquery.js
Dependency Hierarchy:
- ❌ jquery-1.4.4.js (Vulnerable Library)
Vulnerability Details
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.
Publish Date: 2013-03-08
URL: CVE-2011-4969
CVSS 2 Score Details (4.3)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: http://www.securitytracker.com/id/1036620
Fix Resolution: The vendor has issued a fix (iLO 3, firmware version 1.88).
The vendor advisory is available at:
http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05232730
Step up your Open Source Security Game with WhiteSource here
CVE-2011-4969 - Medium Severity Vulnerability
jquery-1.4.2.min.js
JavaScript library for DOM operations
path: /muzich/web/js/jConfirmAction/jquery-1.4.2.min.js
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jquery/1.4.2/jquery.min.js
Dependency Hierarchy:
jquery-1.4.4.js
JavaScript library for DOM operations
path: /muzich/web/bundles/sonatajquery/jquery-1.4.4.js
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jquery/1.4.4/jquery.js
Dependency Hierarchy:
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.
Publish Date: 2013-03-08
URL: CVE-2011-4969
Base Score Metrics not available
Type: Upgrade version
Origin: http://www.securitytracker.com/id/1036620
Fix Resolution: The vendor has issued a fix (iLO 3, firmware version 1.88).
The vendor advisory is available at:
http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05232730
Step up your Open Source Security Game with WhiteSource here