4.3
CVSSv2

CVE-2010-4873

Published: 07/10/2011 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote malicious users to inject arbitrary web script or HTML via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

webidsupport webid 0.8.5

Exploits

source: wwwsecurityfocuscom/bid/44765/info WeBid is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input These vulnerabilities include a local file-include vulnerability and a cross-site-scripting vulnerability Exploiting these issues can allow an attacker to execute arbitrary s ...