First published: Fri Oct 07 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the "official twitter tweet button for your page" (tweetbutton) extension before 1.0.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TweetButton | <=1.0.4 | |
TweetButton | =1.0.0 | |
TweetButton | =1.0.2 | |
TweetButton | =1.0.3 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4886 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To resolve CVE-2010-4886, upgrade the Twitter Tweet Button extension to version 1.0.5 or later.
CVE-2010-4886 affects versions 1.0.0 through 1.0.4 of the TweetButton extension for TYPO3.
CVE-2010-4886 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2010-4886 can be exploited remotely by attackers to execute arbitrary scripts in users' browsers.