4.3
CVSSv2

CVE-2010-3294

Published: 24/09/2010 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in apc.php in the Alternative PHP Cache (APC) extension prior to 3.1.4 for PHP allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

pecl-php alternative php cache 3.0.12

pecl-php alternative php cache 3.0.0

pecl-php alternative php cache 3.0.10

pecl-php alternative php cache 3.0.6

pecl-php alternative php cache 2.0.3

pecl-php alternative php cache 3.0.2

pecl-php alternative php cache 3.1.2

pecl-php alternative php cache 3.0.7

pecl-php alternative php cache 2.0

pecl-php alternative php cache

pecl-php alternative php cache 3.0.1

pecl-php alternative php cache 2.0.4

pecl-php alternative php cache 3.0.4

pecl-php alternative php cache 3.0.15

pecl-php alternative php cache 3.1.3

pecl-php alternative php cache 3.0.11

pecl-php alternative php cache 3.0.17

pecl-php alternative php cache 3.0.18

pecl-php alternative php cache 2.0.2

pecl-php alternative php cache 3.0.9

pecl-php alternative php cache 3.0.16

pecl-php alternative php cache 3.0.13

pecl-php alternative php cache 3.0.19

pecl-php alternative php cache 3.0.14

pecl-php alternative php cache 3.0.3

pecl-php alternative php cache 3.0.8

pecl-php alternative php cache 3.0.5

pecl-php alternative php cache 3.1.1

Vendor Advisories

Synopsis Low: php-pecl-apc security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic Updated php-pecl-apc packages that fix one security issue, several bugs,and add various enhancements are now available for Red Hat EnterpriseLinux 6The Red Hat Security Response Team has rated th ...
A cross-site scripting (XSS) flaw was found in the "apcphp" script, which provides a detailed analysis of the internal workings of APC and is shipped as part of the APC extension documentation A remote attacker could possibly use this flaw to conduct a cross-site scripting attack (CVE-2010-3294) ...