CVE-2011-5249
Cross-site scripting (XSS) vulnerability in the events page in the System iNtrusion Analysis and Reporting Environment (SNARE) for Linux agent before 1.7.0 allows remote attackers to inject arbitrary web script or HTML via a logged shell command.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0020 (0.2%)
Percentile: 41.7%
EPSS: 2026-05-06
Affects
intersectalliance:system_intrusion_analysis_and_reporting_environmentTechnical description
Cross-site scripting (XSS) vulnerability in the events page in the System iNtrusion Analysis and Reporting Environment (SNARE) for Linux agent before 1.7.0 allows remote attackers to inject arbitrary web script or HTML via a logged shell command.
Published: 5/14/2014, 7:55:06 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://archives.neohapsis.com/archives/bugtraq/2012-12/0077.html
- http://rpmfind.net/linux/RPM/sourceforge/s/sn/snare/Snare%20for%20Linux/1.7.0/SnareLinux-1.7.0-0.i386.html
- http://archives.neohapsis.com/archives/bugtraq/2012-12/0077.html
- http://rpmfind.net/linux/RPM/sourceforge/s/sn/snare/Snare%20for%20Linux/1.7.0/SnareLinux-1.7.0-0.i386.html