Vulnerabilities > CVE-2011-0399 - Unspecified vulnerability in Matomo
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Piwik before 1.1 does not prevent the rendering of the login form inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
Vulnerable Configurations
References
- http://dev.piwik.org/trac/ticket/1679
- http://osvdb.org/70383
- http://piwik.org/blog/2011/01/piwik-1-1-2/
- http://www.securityfocus.com/bid/45787
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64640
- http://dev.piwik.org/trac/ticket/1679
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64640
- http://www.securityfocus.com/bid/45787
- http://piwik.org/blog/2011/01/piwik-1-1-2/
- http://osvdb.org/70383