CVE-2010-3447: XSS
Published Apr 1, 2011
·Updated
Cross-site scripting (XSS) vulnerability in view.php in the file viewer in Horde Gollem before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the file parameter in a viewfile action.
Affected Software
14 affected components
Horde Gollem=1.0-rc1
Horde Gollem=1.0-alpha
Horde Gollem=1.0-rc2
Horde Gollem=1.0
Horde Gollem=1.0.2
Horde Gollem=1.1
Horde Gollem=1.1-rc1
Horde Gollem=1.0-beta
Horde Gollem=1.0.3
Horde Gollem<=1.1.1
Horde Gollem=1.0.2-rc1
Horde Gollem=1.0.1
Horde Gollem=1.0.1-rc1
Horde Gollem=1.0.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Apr 1, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3447?
CVE-2010-3447 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2010-3447?
To fix CVE-2010-3447, upgrade Horde Gollem to version 1.1.2 or later.
3
What systems are affected by CVE-2010-3447?
CVE-2010-3447 affects multiple versions of Horde Gollem, specifically versions up to 1.1.1.
4
What type of vulnerability is CVE-2010-3447?
CVE-2010-3447 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2010-3447 lead to data theft?
Yes, CVE-2010-3447 can lead to data theft as attackers can inject arbitrary web scripts.