4.3
CVSSv2

CVE-2010-4913

Published: 08/10/2011 Updated: 14/02/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote malicious users to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

coldgen coldusergroup 1.06

Exploits

#!/usr/bin/python # ColdGen - coldusergroup v106 0day Remote Blind SQL Injection Exploit # Vendor: wwwcoldgencom/ # Found by: mr_me # -----------------------------------------------> # Script provided 'as is', without any warranty # Use for educational purposes only # Do not use this code to do anything illegal ! # ------------------ ...