CVE-2010-1707: XSS
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mailaddress parameters.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1707?
CVE-2010-1707 has a medium severity rating due to multiple cross-site scripting vulnerabilities that allow attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2010-1707?
To fix CVE-2010-1707, upgrade to Piwigo version 2.1 or later, where the vulnerabilities have been addressed.
Which versions of Piwigo are affected by CVE-2010-1707?
CVE-2010-1707 affects Piwigo versions 2.0.9 and earlier, including earlier versions like 1.0.0 up to 2.0.9.
What are the specific parameters involved in CVE-2010-1707?
The specific parameters involved in CVE-2010-1707 are the 'login' and 'mail_address' fields in register.php.
Can CVE-2010-1707 be exploited remotely?
Yes, CVE-2010-1707 can be exploited remotely by attackers to execute malicious scripts in the context of a user's browser.