CVE-2010-0997: XSS
Published Apr 20, 2010
·Updated
Cross-site scripting (XSS) vulnerability in 107plugins/content/contentmanager.php in the Content Management plugin in e107 before 0.7.20, when the personal content manager is enabled, allows user-assisted remote authenticated users to inject arbitrary web script or HTML via the contentheading parameter.
Affected Software
20 affected components
e107 e107<=0.7.19
e107 e107=0.7.0
e107 e107=0.7.1
e107 e107=0.7.2
e107 e107=0.7.3
e107 e107=0.7.4
e107 e107=0.7.5
e107 e107=0.7.6
e107 e107=0.7.7
e107 e107=0.7.8
e107 e107=0.7.9
e107 e107=0.7.10
e107 e107=0.7.11
e107 e107=0.7.12
e107 e107=0.7.13
e107 e107=0.7.14
e107 e107=0.7.15
e107 e107=0.7.16
e107 e107=0.7.17
e107 e107=0.7.18
Remediation
Patch Available
Event History
Apr 20, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0997?
CVE-2010-0997 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2010-0997?
To fix CVE-2010-0997, upgrade to e107 version 0.7.20 or later.
3
What type of vulnerability is CVE-2010-0997?
CVE-2010-0997 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2010-0997?
Users of e107 versions prior to 0.7.20 with the personal content manager enabled are affected by CVE-2010-0997.
5
Can CVE-2010-0997 be exploited remotely?
CVE-2010-0997 can potentially be exploited by remote authenticated users.