CVE-2010-4504: XSS
Multiple cross-site scripting (XSS) vulnerabilities in eSyndiCat Directory 2.3 allow remote attackers to inject arbitrary web script or HTML via the title parameter to (1) suggest-category.php and (2) suggest-listing.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4504?
CVE-2010-4504 has a medium severity rating due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2010-4504?
To fix CVE-2010-4504, it is recommended to sanitize user input in the title parameter for suggest-category.php and suggest-listing.php.
What systems are affected by CVE-2010-4504?
CVE-2010-4504 specifically affects eSyndiCat Directory version 2.3.
What are the potential impacts of CVE-2010-4504?
CVE-2010-4504 can allow attackers to inject malicious scripts into the web application, potentially leading to data theft or user session hijacking.
How can I identify CVE-2010-4504 on my system?
You can identify CVE-2010-4504 by checking for the presence of eSyndiCat Directory version 2.3 and testing for XSS vulnerabilities in the suggested category and listing forms.