CVE-2010-1068: XSS
Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1068?
CVE-2010-1068 is classified as a medium-severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2010-1068?
To mitigate CVE-2010-1068, update to a version of SurgeFTP that corrects the cross-site scripting vulnerabilities.
What are the attack vectors for CVE-2010-1068?
Attackers can exploit CVE-2010-1068 by injecting malicious scripts through the domainid or classid parameters in class actions.
Who is affected by CVE-2010-1068?
CVE-2010-1068 affects users of NetWin SurgeFTP version 2.3a6.
Can CVE-2010-1068 lead to data theft?
Yes, successful exploitation of CVE-2010-1068 can allow attackers to steal session cookies or perform actions on behalf of users.