Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-4197

EPSS 0.90% · P76
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-4197

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
pfSense 跨站脚本漏洞和安全绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Electric Sheep Fencing pfsense是美国Electric Sheep Fencing公司的一套免费开源的基于FreeBSD的防火墙和路由器软件。 pfSense中存在跨站脚本漏洞和安全绕过漏洞。攻击者可利用跨站脚本漏洞在受影响站点上下文的不知情用户浏览器中执行任意脚本代码,窃取基于cookie的认证证书进而发起其他攻击;也可利用安全绕过漏洞绕过某些安全限制进而执行未授权操作。pfSense 2.0版本中存在该漏洞,其他版本也可能受影响。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-4197

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-4197

Please Login to view more intelligence information

Same Patch Batch · n/a · 2012-01-03 · 7 CVEs total

CVE-2011-5047pfsense ‘status_rrd_graph.php’ 跨站脚本漏洞
CVE-2011-5048IBM Web Experience Factory跨站脚本漏洞
CVE-2011-4642Splunk ‘Splunk Web’跨站请求伪造漏洞
CVE-2011-4643Splunk路径遍历漏洞
CVE-2011-4644Splunk授权问题漏洞
CVE-2011-4778Splunk跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-4197

No comments yet


Leave a comment