CVE-2011-1034
IBM Rational Build Forge 7.0.2 - Cross-Site Scripting via mod Parameter
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third party information.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1025019
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43180
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0276
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/46125
Various Sources vendor-advisory
x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1PM05187
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/70763
Scores
EPSS
0.0122
EPSS Percentile
65.6%
Details
CWE
CWE-79
Status
published
Products (1)
ibm/rational_build_forge
7.0.2
Published
Feb 16, 2011
Tracked Since
Feb 18, 2026