CVE-2011-4335
Contao <2.10.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) teachers.html or (2) teachers/ action.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Stefan Schurtz · textwebappsphp
https://www.exploit-db.com/exploits/36225
References (5)
Scores
EPSS
0.0043
EPSS Percentile
62.3%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
contao/contao_cms
< 2.10.1
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
contao/contao_cms
... and 35 more
Timeline
Published
Nov 28, 2011
Tracked Since
Feb 18, 2026