Name | CVE-2011-3361 |
Description | Cross-site scripting (XSS) vulnerability in CGI/Browse.pm in BackupPC 3.2.0 and possibly other versions before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a browse action to index.cgi. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 641450 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
backuppc (PTS) | jessie | 3.3.0-2+deb8u1 | fixed |
| stretch | 3.3.1-4 | fixed |
| buster | 3.3.2-2+deb10u1 | fixed |
| bullseye | 4.4.0-3 | fixed |
| bookworm | 4.4.0-8 | fixed |
| sid, trixie | 4.4.0-10 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
backuppc | source | squeeze | 3.1.0-9.1 | | | |
backuppc | source | (unstable) | 3.2.1-2 | | | 641450 |
Notes
http://sourceforge.net/mailarchive/forum.php?thread_name=f1f1ef74-716d-4af8-b1bf-c1ba6d9a98a1%40SC1EXHC-02.global.atheros.com&forum_name=backuppc-devel
http://backuppc.cvs.sourceforge.net/viewvc/backuppc/BackupPC/lib/BackupPC/CGI/Browse.pm?r1=1.23&r2=1.24