Low severityNVD Advisory· Published Mar 29, 2011· Updated Jun 16, 2026
CVE-2011-0728
CVE-2011-0728
Description
Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
loggerheadPyPI | < 1.18.1 | 1.18.1 |
Affected products
6cpe:2.3:a:michael_hudson-doyle:loggerhead:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:michael_hudson-doyle:loggerhead:*:*:*:*:*:*:*:*range: <=1.18
- cpe:2.3:a:michael_hudson-doyle:loggerhead:1.10:*:*:*:*:*:*:*
- cpe:2.3:a:michael_hudson-doyle:loggerhead:1.17:*:*:*:*:*:*:*
- cpe:2.3:a:michael_hudson-doyle:loggerhead:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:michael_hudson-doyle:loggerhead:1.6.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
15- bugs.launchpad.net/loggerhead/+bug/740142nvdPatchWEB
- launchpad.net/loggerhead/1.18/1.18.1nvdPatchWEB
- secunia.com/advisories/43822nvdVendor Advisory
- github.com/advisories/GHSA-qjmg-77xh-7mjwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2011-0728ghsaADVISORY
- lists.fedoraproject.org/pipermail/package-announce/2011-April/057413.htmlnvdWEB
- lists.fedoraproject.org/pipermail/package-announce/2011-April/057479.htmlnvdWEB
- lists.fedoraproject.org/pipermail/package-announce/2011-April/057502.htmlnvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/66305nvdWEB
- web.archive.org/web/20200228162139/http://www.securityfocus.com/bid/47032ghsaWEB
- secunia.com/advisories/44017nvd
- www.osvdb.org/71279nvd
- www.securityfocus.com/bid/47032nvd
- www.vupen.com/english/advisories/2011/0848nvd
- www.vupen.com/english/advisories/2011/0849nvd
News mentions
0No linked articles in our index yet.