4.3
CVSSv2

CVE-2010-3890

Published: 12/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition prior to 9.1 allows remote malicious users to inject arbitrary web script or HTML via the command parameter to the administration interface, as demonstrated by the command parameter to ESAdmin/collection.do.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm omnifind 8.5

ibm omnifind

ibm omnifind 8.0

ibm omnifind 8.4

Exploits

IBM OmniFind suffers from cross site scripting, cross site request forgery, buffer overflow, session fixation and privilege escalation vulnerabilities Various other issues also exist ...