All current released versions of Samba are vulnerable to a cross-site
scripting issue in the Samba Web Administration Tool (SWAT). On the "Change
Password" field, it is possible to insert arbitrary content into the "user"
field.
This issue is only exploitable if CVE-2011-2522 has not been fixed.
Vendor Status:
Samba had issued an update for this vulnerability.
Patch Availability:
A patch addressing this defect has been posted to