CVE-2011-1034

IBM Rational Build Forge 7.0.2 - Cross-Site Scripting via mod Parameter

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third party information.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1025019
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43180
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0276
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46125
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1PM05187
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/70763

Scores

EPSS 0.0122
EPSS Percentile 65.6%

Details

CWE
CWE-79
Status published
Products (1)
ibm/rational_build_forge 7.0.2
Published Feb 16, 2011
Tracked Since Feb 18, 2026