CVE-2010-2858
Published Jul 25, 2010
Last updated 6 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:boesch-it:simpnews:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57B891F3-1B6D-4039-BF4D-E4D6F3AB6FDC", "versionEndIncluding": "2.47.03" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8CADEFF-8D12-4308-9C2A-F37AE60DC499" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D37D1345-2566-417F-88A3-4B8DADB6161D" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "525D4258-6B60-4902-A0EF-B6E3BDBC1875" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.30.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C35A9176-BF2E-43C2-BD36-3F583362DAF5" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.30.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35ECC5A8-CCCC-4E1E-875E-FC0D28AD964D" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.31.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BAD35679-9229-4A35-8638-56C7B110FEE3" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.32.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09F7499C-C884-4770-A112-D5FE69B5C55B" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.32.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3744273B-0CDC-4DBF-807F-8614CC0C1A66" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.33.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6224286D-47EE-4F2E-80DF-9ACDB54A3E24" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.33.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1C4FFA6-3DC6-4139-983C-5B112F7779BB" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.34:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83F2C8B0-C422-4504-88A9-597433D79452" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.34.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD3E663C-875D-4F3C-985C-DC81314859AD" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.34.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB2DCF08-B334-49F3-BF9D-11A07658F844" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.35.00:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2BE4191A-F0F5-496A-850E-03D8C76463C1" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.36.00:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3355919-74E6-4875-82E7-2BCCCC2D7444" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.37.00:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17CF2904-694A-4B4F-8A3C-94B6A4F17897" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.37.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "655848C4-060B-46ED-8151-8A5C275AAF53" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.37.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2F66B4A-DB1D-4D30-A05C-A015F2454949" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.38:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55C91B08-1352-48D8-87B6-EC5D8FFACA2A" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.38.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B3B1AF1-9F9D-4740-9974-94677588821D" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.38.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "780E0AA5-F5D8-409E-8EA1-96936127DB91" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.38.04:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B54AD3F-C179-4208-A671-1D042D4B5B35" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.39.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7333ECDA-75E1-4A3E-8E38-5AB007E43757" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.40.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0AD0E0D-C78F-4150-8EE7-FA13D6B259BF" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.41.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51FDD925-6E20-4C34-94B3-3F7B66CE1091" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.41.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DBE88F68-D48F-4A34-BBA3-094AA24CB846" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.41.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C36114C-FB58-461A-845C-E49A4633B65E" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.42.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B3A9534-C955-441F-8D0D-28E8C86D0936" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.42.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "163E21A7-F4B2-46AF-AAF6-7450C5D68F42" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.44.00:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B9B43B1-5E68-431F-A0A0-ABD1341CDFE4" }, { "criteria": "cpe:2.3:a:boesch-it:simpnews:2.47.00:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC72F4DE-1D7B-4212-AA9E-E764004C5109" } ], "operator": "OR" } ] } ]