First published: Mon Oct 18 2010(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the rev parameter to the view script or (2) the query string to the login script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TWiki | =2000-12-01 | |
TWiki | =2004-09-02 | |
TWiki | =4.1.1 | |
TWiki | =4.0.1 | |
TWiki | =4.2.3 | |
TWiki | =4.2.4 | |
TWiki | =2001-09-01 | |
TWiki | <=5.0.0 | |
TWiki | =4.3.0 | |
TWiki | =4.3.2 | |
TWiki | =2003-02-01 | |
TWiki | =4.0.3 | |
TWiki | =4.0.4 | |
TWiki | =2001-12-01 | |
TWiki | =2004-09-04 | |
TWiki | =2004-09-01 | |
TWiki | =2004-09-03 | |
TWiki | =4.0.0 | |
TWiki | =4.1.0 | |
TWiki | =4.3.1 | |
TWiki | =4.2.2 | |
TWiki | =4.0.2 | |
TWiki | =4.0.5 | |
TWiki | =4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3841 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2010-3841, upgrade to TWiki version 5.0.1 or later, where this vulnerability has been addressed.
CVE-2010-3841 can enable remote attackers to inject arbitrary web script or HTML, potentially leading to stolen session cookies or site defacement.
CVE-2010-3841 affects TWiki versions prior to 5.0.1, including various versions from 2000-12-01 up to 4.3.2.
The affected components related to CVE-2010-3841 include the view script's rev parameter and the query string in the login script.