4.3
CVSSv2

CVE-2010-2265

Published: 15/06/2010 Updated: 26/02/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote malicious users to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 2003 server

microsoft windows xp

microsoft windows xp -

microsoft windows server 2003

Exploits

source: wwwsecurityfocuscom/bid/40721/info Help and Support Center is prone to a cross-site scripting weakness because it fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the privileged zone of the browser of an unsuspecting user NOTE: This issue is a weakness becau ...