Lucene search

K
cve[email protected]CVE-2010-2265
HistoryJun 15, 2010 - 2:04 p.m.

CVE-2010-2265

2010-06-1514:04:24
CWE-79
web.nvd.nist.gov
31
cve
2010
2265
cross-site scripting
xss
vulnerability
microsoft
windows
help and support center
windows xp
windows server 2003
remote attackers
arbitrary web script
html
sysinfo
sysinfomain.htm
cve-2010-1885
arbitrary commands

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

High

EPSS

0.974

Percentile

99.9%

Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.

Affected configurations

NVD
Node
microsoftwindows_2003_serversp2
OR
microsoftwindows_2003_serversp2itanium
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp3
OR
microsoftwindows_xpMatch-sp2x64
VendorProductVersionCPE
microsoftwindows_server_2003cpe:/o:microsoft:windows_server_2003::sp2::
microsoftwindows_xpcpe:/o:microsoft:windows_xp::sp3::
microsoftwindows_xp-cpe:/o:microsoft:windows_xp:-:sp2::
microsoftwindows_xpcpe:/o:microsoft:windows_xp::sp2::
microsoftwindows_2003_servercpe:/o:microsoft:windows_2003_server::sp2::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

High

EPSS

0.974

Percentile

99.9%