Lucene search

K
cveMitreCVE-2010-5302
HistoryAug 21, 2014 - 11:55 p.m.

CVE-2010-5302

2014-08-2123:55:02
CWE-79
mitre
web.nvd.nist.gov
21
cve-2010-5302
xss
timthumb
web script
html
query_string
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

50.2%

Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb before 1.15 as of 20100908 (r88), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.

Affected configurations

Nvd
Node
binarymoontimthumbRange1.09
VendorProductVersionCPE
binarymoontimthumb*cpe:2.3:a:binarymoon:timthumb:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

50.2%

Related for CVE-2010-5302