4.3
CVSSv2

CVE-2011-1168

Published: 18/04/2011 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the KHTMLPart::htmlError function in khtml/khtml_part.cpp in Konqueror in KDE SC 4.4.0 up to and including 4.6.1 allows remote malicious users to inject arbitrary web script or HTML via the URI in a URL corresponding to an unavailable web site.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde sc 4.5.2

kde kde sc 4.4.0

kde kde sc 4.6

kde kde sc 4.5.4

kde kde sc 4.4.1

kde kde sc 4.4.2

kde kde sc 4.5.5

kde kde sc 4.5.1

kde kde sc 4.4.3

kde kde sc 4.6.1

kde kde sc 4.4.4

kde kde sc 4.5.3

kde kde sc 4.4.5

kde kde sc 4.6.0

kde kde sc 4.5.0

Vendor Advisories

An attacker could send crafted input to Konqueror to view sensitive information ...

Exploits

Nth Dimension Security Advisory (NDSA20110321) - Konqueror versions 44x, 45x, and 46x suffer from an HTML injection vulnerability ...