MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Proxy Granting Ticket IOU (PGTiou) parameter to the callback function in client.php, (2) vectors involving functions that make getCallbackURL calls, or (3) vectors involving functions that make getURL calls
Published Oct 7, 2010
4.3
MEDIUMCVSS 2.0
EPSS 2.51%
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Proxy Granting Ticket IOU (PGTiou) parameter to the callback function in client.php, (2) vectors involving functions that make getCallbackURL calls, or (3) vectors involving functions that make getURL calls.
Affected products
No data.
OR
- ≤ 1.1.2
- 0.2
- 0.3
- 0.3.1
- 0.3.2
- 0.4
- 0.4.1
- 0.4.8
- 0.4.9
- 0.4.10
- 0.4.11
- 0.4.12
- 0.4.13
- 0.4.14
- 0.4.15
- 0.4.16
- 0.4.17
- 0.4.18
- 0.4.19
- 0.4.20
- 0.4.21
- 0.4.22
- 0.4.23
- 0.5.0
- 0.5.1
- 0.6.0
- 1.0.0
- 1.0.1
- 1.1.0
- 1.1.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (20)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495542#82 x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050415.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050428.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049600.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049602.html vendor-advisoryx_refsource_FEDORA
- http://secunia.com/advisories/41878 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42149 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42184 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43427 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2011/dsa-2172 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2010/09/29/6 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2010/10/01/2 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2010/10/01/5 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/43585 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2010/2705 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/2909 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0456 vdb-entryx_refsource_VUPEN
- https://developer.jasig.org/source/changelog/jasigsvn?cs=21538 x_refsource_CONFIRM
- https://forge.indepnet.net/projects/glpi/repository/revisions/12601 x_refsource_CONFIRM
- https://issues.jasig.org/browse/PHPCAS-80 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 7, 2010
Updated Aug 7, 2024
Reserved Oct 1, 2010
Link CVE-2010-3690
CISA Vulnrichment
Updated n/a