Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-2477
HistoryNov 05, 2010 - 12:00 a.m.

CVE-2010-2477

2010-11-0500:00:00
ubuntu.com
ubuntu.com
6

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

69.9%

Multiple cross-site scripting (XSS) vulnerabilities in the
paste.httpexceptions implementation in Paste before 1.7.4 allow remote
attackers to inject arbitrary web script or HTML via vectors involving a
404 status code, related to (1) paste.urlparser.StaticURLParser, (2)
paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4)
HTTPNotFound.

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchpaste< 1.7.2-4ubuntu1.2UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

69.9%