Unrated severityNVD Advisory· Published Jun 2, 2011· Updated Jun 16, 2026
CVE-2011-1077
CVE-2011-1077
Description
Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:apache:archiva:1.0:*:*:*:*:*:*:*+ 18 more
- cpe:2.3:a:apache:archiva:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.2-m1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:archiva:1.3.4:*:*:*:*:*:*:*
- (no CPE)range: <=1.2.2, >=1.3.0 <1.3.5
Patches
Vulnerability mechanics
References
8- archives.neohapsis.com/archives/fulldisclosure/2011-05/0531.htmlnvdExploit
- archiva.apache.org/security.htmlnvdVendor Advisory
- secunia.com/advisories/44693nvdVendor Advisory
- archiva.apache.org/docs/1.3.5/release-notes.htmlnvd
- securityreason.com/securityalert/8267nvd
- www.securityfocus.com/archive/1/518167/100/0/threadednvd
- www.securityfocus.com/bid/48011nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/67672nvd
News mentions
0No linked articles in our index yet.