← Volver a CVEs
CVE-2010-4757
N/ADescripcion
Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnews_title parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obtained from third party information. NOTE: this might be the same as CVE-2009-4083.1 or CVE-2011-0457.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado3/15/2011
Ultima modificacion4/29/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
e107:e107
Debilidades (CWE)
CWE-79
Referencias
http://e107.org/comment.php?comment.news.872(cve@mitre.org)
http://e107.org/svn_changelog.php?version=0.7.23(cve@mitre.org)
http://e107.svn.sourceforge.net/viewvc/e107/trunk/e107_0.7/e107_admin/newspost.php?r1=11655&r2=11654&pathrev=11655(cve@mitre.org)
http://securitytracker.com/id?1024351(cve@mitre.org)
http://www.madirish.net/?article=471(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/61331(cve@mitre.org)
http://e107.org/comment.php?comment.news.872(af854a3a-2127-422b-91ae-364da2661108)
http://e107.org/svn_changelog.php?version=0.7.23(af854a3a-2127-422b-91ae-364da2661108)
http://e107.svn.sourceforge.net/viewvc/e107/trunk/e107_0.7/e107_admin/newspost.php?r1=11655&r2=11654&pathrev=11655(af854a3a-2127-422b-91ae-364da2661108)
http://securitytracker.com/id?1024351(af854a3a-2127-422b-91ae-364da2661108)
http://www.madirish.net/?article=471(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/61331(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.