4.3
CVSSv2

CVE-2010-3841

Published: 18/10/2010 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki prior to 5.0.1 allow remote malicious users to inject arbitrary web script or HTML via (1) the rev parameter to the view script or (2) the query string to the login script.

Vulnerable Product Search on Vulmon Subscribe to Product

twiki twiki 4.0.1

twiki twiki 4.0.2

twiki twiki 4.0.3

twiki twiki 4.2.3

twiki twiki 4.2.4

twiki twiki 2003-02-01

twiki twiki 2004-09-01

twiki twiki 4.1.0

twiki twiki 4.1.1

twiki twiki 4.3.2

twiki twiki 2000-12-01

twiki twiki 2004-09-04

twiki twiki

twiki twiki 4.0.4

twiki twiki 4.0.5

twiki twiki 4.3.0

twiki twiki 4.3.1

twiki twiki 2004-09-02

twiki twiki 2004-09-03

twiki twiki 4.0.0

twiki twiki 4.1.2

twiki twiki 4.2.2

twiki twiki 2001-09-01

twiki twiki 2001-12-01

Exploits

source: wwwsecurityfocuscom/bid/44103/info TWiki is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may allow the at ...
source: wwwsecurityfocuscom/bid/44103/info TWiki is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may allow the atta ...