CVE-2010-4246: XSS
Published Dec 7, 2010
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in graph.php in pfSense 1.2.3 and 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via the (1) ifnum or (2) ifname parameter, a different vulnerability than CVE-2008-1182.
Affected Software
2 affected components
Bsdperimeter Pfsense=2.0-beta4
Bsdperimeter Pfsense=1.2.3
Event History
Dec 7, 2010
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4246?
CVE-2010-4246 is classified as a medium severity vulnerability due to its potential impact on user data integrity.
2
How do I fix CVE-2010-4246?
To mitigate CVE-2010-4246, upgrade pfSense to a patched version that addresses this XSS vulnerability.
3
What are the affected versions of pfSense for CVE-2010-4246?
CVE-2010-4246 affects pfSense versions 1.2.3 and 2.0 beta 4.
4
What type of vulnerability is CVE-2010-4246?
CVE-2010-4246 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
5
Can CVE-2010-4246 be exploited remotely?
Yes, CVE-2010-4246 can be exploited remotely by attackers to inject arbitrary web scripts.