2.6
CVSSv2

CVE-2010-1515

Published: 15/06/2010 Updated: 18/06/2010
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) keyword or (2) article-id parameter in conjunction with a /admin/news/article/list PATH_INFO; the (3) keyword parameter in conjunction with a /admin/multimedia/set/list PATH_INFO; the (4) keyword or (5) fileId parameter in conjunction with a /admin/multimedia/file/list PATH_INFO; or the (6) name, (7) email, or (8) address parameter in conjunction with a /admin/ad/client/list PATH_INFO.

Vulnerable Product Search on Vulmon Subscribe to Product

tomatocms tomatocms 2.0.0

tomatocms tomatocms 2.0.2

tomatocms tomatocms 2.0.3.1622

tomatocms tomatocms 2.0.3.1430

tomatocms tomatocms 2.0.4

tomatocms tomatocms 2.0.1

tomatocms tomatocms 2.0.5

tomatocms tomatocms 2.0.3

tomatocms tomatocms