Arbitrary Web Script Injection in Kiwi before 3.74.2

Arbitrary Web Script Injection in Kiwi before 3.74.2

CVE-2011-2644 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.

Learn more about our Web App Pen Testing.