Lucene search

K
cvelistMitreCVELIST:CVE-2010-4607
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-4607

2022-10-0316:21:03
mitre
www.cve.org
cve-2010-4607
cross-site scripting
habari 0.6.5
remote attackers
web script injection
html injection

5.8 Medium

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.1%

Multiple cross-site scripting (XSS) vulnerabilities in Habari 0.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) additem_form parameter to system/admin/dash_additem.php and the (2) status_data[] parameter to system/admin/dash_status.php. NOTE: some of these details are obtained from third party information.

5.8 Medium

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.1%

Related for CVELIST:CVE-2010-4607