CVE-2010-3314
Published Sep 22, 2010
Last updated 14 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:egroupware:egroupware:1.4.001:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F22F0392-6D7A-4133-83AA-C14F1B69A167" }, { "criteria": "cpe:2.3:a:egroupware:egroupware:1.4.001\\+.002:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65987EB6-F4D8-47C9-B95F-DEA15E94A3AD" }, { "criteria": "cpe:2.3:a:egroupware:egroupware:1.4.002:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "896271FE-50B1-436B-8926-1CE685667D03" }, { "criteria": "cpe:2.3:a:egroupware:egroupware:1.6.001:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7AE768DF-9605-40FA-8840-C60D2C0DCE0F" }, { "criteria": "cpe:2.3:a:egroupware:egroupware:1.6.001\\+.002:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C105EFE2-0592-45B3-A362-4208245EDD9C" }, { "criteria": "cpe:2.3:a:egroupware:egroupware:1.6.002:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDB7B153-61AE-499D-8577-CC83CC100C43" }, { "criteria": "cpe:2.3:a:egroupware:egroupware:9.1:-:commercial_epl:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C9D0492E-A33E-43D4-8E57-C74D677A1B99" }, { "criteria": "cpe:2.3:a:egroupware:egroupware:9.2:-:commercial_epl:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37AD8770-074D-42E3-81CC-E3A7D8856FD2" } ], "operator": "OR" } ] } ]