Lucene search

K
cveMitreCVE-2010-2032
HistoryMay 24, 2010 - 7:30 p.m.

CVE-2010-2032

2010-05-2419:30:01
CWE-79
mitre
web.nvd.nist.gov
29
cve-2010-2032
cross-site scripting
xss
caucho technology
resin professional
vulnerability
remote attackers
web script
html
third party information

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.007

Percentile

81.2%

Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_username parameters. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
cauchoresinMatch3.1.5-pro
OR
cauchoresinMatch3.1.10-pro
OR
cauchoresinMatch4.0.6-pro
VendorProductVersionCPE
cauchoresin3.1.5cpe:2.3:a:caucho:resin:3.1.5:-:pro:*:*:*:*:*
cauchoresin3.1.10cpe:2.3:a:caucho:resin:3.1.10:-:pro:*:*:*:*:*
cauchoresin4.0.6cpe:2.3:a:caucho:resin:4.0.6:-:pro:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.007

Percentile

81.2%