Medium severity6.1NVD Advisory· Published Feb 11, 2020· Updated Jun 16, 2026
CVE-2011-4938
CVE-2011-4938
Description
Multiple cross-site scripting (XSS) vulnerabilities in Ariadne 2.7.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) index.php and (2) loader.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- seclists.org/bugtraq/2011/Dec/7nvdExploitMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2012/03/09/4nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2012/03/10/6nvdMailing ListThird Party Advisory
- bugs.ariadne-cms.org/view.phpnvdBroken Link
- www.rul3z.de/advisories/SSCHADV2011-038.txtnvdNot Applicable
News mentions
0No linked articles in our index yet.