2.6
CVSSv2

CVE-2010-0132

Published: 31/03/2010 Updated: 10/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in ViewVC 1.1 prior to 1.1.5 and 1.0 prior to 1.0.11, when the regular expression search functionality is enabled, allows remote malicious users to inject arbitrary web script or HTML via vectors related to "search_re input," a different vulnerability than CVE-2010-0736.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

viewvc viewvc 1.0.5

viewvc viewvc 1.0.6

viewvc viewvc 1.1.0

viewvc viewvc 1.0.3

viewvc viewvc 1.0.4

viewvc viewvc 1.0.1

viewvc viewvc 1.0.0

viewvc viewvc 1.1.1

viewvc viewvc 1.1.2

viewvc viewvc 1.1.3

viewvc viewvc 1.0.7

viewvc viewvc 1.0.8

viewvc viewvc 1.1.4

viewvc viewvc 1.0.2

viewvc viewvc 1.0.9

viewvc viewvc 1.0.10

Vendor Advisories

Debian Bug report logs - #575777 CVE-2010-0004 CVE-2010-0005 Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Mon, 29 Mar 2010 07:54:02 UTC Severity: serious Tags: security Fi ...
Debian Bug report logs - #576307 CVE-2010-0132: XSS via user-provided 'search_re' input Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 2 Apr 2010 20:51:02 UTC Severity: gra ...
Debian Bug report logs - #575787 CVE-2010-0736: Cross-site scripting (XSS) vulnerability Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Mon, 29 Mar 2010 09:12:02 UTC Severity ...