4.3
CVSSv2

CVE-2010-4850

Published: 27/09/2011 Updated: 14/02/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote malicious users to inject arbitrary web script or HTML via the (1) post_content parameter to post/edit/2/p1.html, related to views/post.php; the (2) slogan parameter to admin/site/2.html, related to views/admin.php; or the (3) subcatname or (4) description parameter to admin/forum/create_sub.html, related to views/admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

diferior diferior 8.03

Exploits

Vulnerability ID: HTB22721 Reference: wwwhtbridgech/advisory/stored_xss_cross_site_scripting_vulnerability_in_diferiorhtml Product: Diferior Vendor: Povilas Musteikis ( wwwdiferiorcom/ ) Vulnerable Version: 803 and probably prior versions Vendor Notification: Vulnerability Type: Stored XSS (Cross Site Scripting) Status: Not Fi ...