Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2010-0736
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-0736

2022-10-0316:21:10
Debian Security Bug Tracker
security-tracker.debian.org
9
cve-2010-0736
xss
viewvc
web script
html
user-provided input
unix

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

60.2%

Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via “user-provided input.”

OSVersionArchitecturePackageVersionFilename
Debian10allviewvc< 1.1.5-1viewvc_1.1.5-1_all.deb

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

60.2%