CVE-2010-1104: XSS
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1104?
CVE-2010-1104 has been classified as a medium-severity vulnerability due to its potential for exploitation through cross-site scripting (XSS).
How do I fix CVE-2010-1104?
To mitigate CVE-2010-1104, upgrade Zope to versions 2.8.12, 2.9.12, 2.10.11, 2.11.6, or 2.12.3 or later, which include patches for this vulnerability.
Who is affected by CVE-2010-1104?
CVE-2010-1104 affects multiple versions of Zope, specifically versions 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3.
What types of attacks can exploit CVE-2010-1104?
CVE-2010-1104 can be exploited by remote attackers to inject arbitrary web scripts or HTML via manipulated error messages.
Is there a workaround for CVE-2010-1104 if I cannot immediately upgrade?
There are no specific workarounds for CVE-2010-1104; therefore, immediate upgrading to a patched version is strongly recommended.