CVE-2010-1382: XSS
Published Jun 17, 2010
·Updated
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users to inject arbitrary web script or HTML via crafted Wiki content, related to lack of a charset field.
Affected Software
10 affected components
Apple iOS and macOS=10.5.8
Apple Mac OS X Server=10.5.8
Apple Mac OS X Server=10.6.3
Apple iOS and macOS=10.6.3
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple iOS and macOS=10.6.1
Apple Mac OS X Server=10.6.0
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.2
Remediation
Patch Available
Patch Available
Event History
Jun 17, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-1382?
CVE-2010-1382 has been classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2010-1382?
To fix CVE-2010-1382, update your Apple Mac OS X to version 10.6.4 or later.
3
Who is affected by CVE-2010-1382?
CVE-2010-1382 affects users of Apple Mac OS X versions 10.5.8 and 10.6.x prior to 10.6.4.
4
What kind of attack can CVE-2010-1382 enable?
CVE-2010-1382 can enable attackers to perform cross-site scripting (XSS) attacks through crafted Wiki content.
5
Is authentication required to exploit CVE-2010-1382?
Yes, CVE-2010-1382 requires remote authenticated users to exploit the vulnerability.