4.3
CVSSv2

CVE-2010-3425

Published: 16/09/2010 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote malicious users to inject arbitrary web script or HTML via the url parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

smartertools smarterstats 5.3.3819

smartertools smarterstats 5.3

Exploits

Source URL cloudscanblogspotcom/2010/10/vendor-smartertoolscom-smartermail-7xhtml ######################################################################## # Vendor: smartertoolscom SmarterMail 7x (723925) # Date: 2010-10-01 # Author : David Hoyt (sqlhacker) – Hoyt LLC # Contact : h02332@gmailcom # Home : cloudscanme # Dork ...
SmarterMail version 7x suffers from cross site scripting, shell upload and directory traversal vulnerabilities ...