4.3
CVSSv2

CVE-2010-3690

Published: 07/10/2010 Updated: 30/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in phpCAS prior to 1.1.3, when proxy mode is enabled, allow remote malicious users to inject arbitrary web script or HTML via (1) a crafted Proxy Granting Ticket IOU (PGTiou) parameter to the callback function in client.php, (2) vectors involving functions that make getCallbackURL calls, or (3) vectors involving functions that make getURL calls.

Vulnerable Product Search on Vulmon Subscribe to Product

apereo phpcas 1.0.1

apereo phpcas 1.0.0

apereo phpcas 0.4.10

apereo phpcas 0.4.16

apereo phpcas 0.4.13

apereo phpcas 0.4.8

apereo phpcas 0.4.23

apereo phpcas

apereo phpcas 0.6.0

apereo phpcas 0.5.1

apereo phpcas 0.4.15

apereo phpcas 0.4.18

apereo phpcas 0.5.0

apereo phpcas 0.4.9

apereo phpcas 0.3.2

apereo phpcas 0.3.1

apereo phpcas 1.1.1

apereo phpcas 1.1.0

apereo phpcas 0.4.11

apereo phpcas 0.4.14

apereo phpcas 0.4.22

apereo phpcas 0.4.21

apereo phpcas 0.4.1

apereo phpcas 0.4

apereo phpcas 0.3

apereo phpcas 0.2

apereo phpcas 0.4.17

apereo phpcas 0.4.12

apereo phpcas 0.4.20

apereo phpcas 0.4.19

Vendor Advisories

Several vulnerabilties have been discovered in phpCAS, a CAS client library for PHP The Moodle course management system includes a copy of phpCAS For the oldstable distribution (lenny), this problem has been fixed in version 1813-3 The stable distribution (squeeze) already contains a fixed version of phpCAS The unstable distribution (sid) alr ...