First published: Mon May 24 2010(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_username parameters. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caucho Technology Resin | =4.0.6 | |
Caucho Technology Resin | =3.1.5 | |
Caucho Technology Resin | =3.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2032 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2010-2032, upgrade to a version of Caucho Technology Resin that is not affected by this vulnerability, such as 4.0.7 or later.
CVE-2010-2032 affects Caucho Technology Resin versions 3.1.5, 3.1.10, and 4.0.6.
CVE-2010-2032 allows remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts through specific parameters.
Yes, CVE-2010-2032 can be exploited remotely by injecting malicious scripts via the affected web interface.