CVE-2010-4155: XSS
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/caferss/example.php and the sumb parameter to (2) modules/news/archive.php, (3) modules/news/topics.php, and (4) modules/contact/index.php, different vectors than CVE-2007-1965.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4155?
CVE-2010-4155 has been classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2010-4155?
To fix CVE-2010-4155, sanitize and validate user inputs in the affected parameters to prevent the injection of malicious scripts.
What software versions are affected by CVE-2010-4155?
CVE-2010-4155 affects eXV2 CMS version 2.10.
What are the attack vectors for CVE-2010-4155?
Attackers can exploit CVE-2010-4155 through crafted URLs that include malicious input in the rssfeedURL and sumb parameters.
Can CVE-2010-4155 allow attacker control over affected systems?
Yes, CVE-2010-4155 can enable attackers to inject scripts that may hijack user sessions or redirect users to malicious sites.