MEDIUM
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php
Published Oct 22, 2012
4.3
MEDIUMCVSS 2.0
EPSS 4.74%
Description
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
Affected products
No data.
OR
- ≤ 2.6.8
- 1.0
- 1.0.1
- 1.0.1a
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.4a
- 1.1.5
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.5a
- 1.2.5b
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.5
- 1.3.6
- 1.3.7
- 1.3.8
- 1.3.9
- 1.3.9
- 1.3.10
- 1.3.11
- 1.3.12
- 1.3.13
- 1.3.14
- 1.4
- 1.4
- 1.4
- 1.4.0
- 1.4.0a
- 1.4.1
- 1.4.2
- 1.4.3
- 1.4.4
- 1.4.5
- 1.4.6
- 1.4.7
- 1.4.8
- 1.4.9
- 1.4.10
- 1.4.11
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5.0
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.5.5
- 1.5.6
- 1.5.7
- 1.5.8
- 1.5.9
- 1.6.0
- 1.6.1
- 1.6.2
- 1.6.3
- 1.6.4
- 1.6.5
- 1.6.6
- 1.6.7
- 1.6.8
- 1.6.9
- 1.6.10
- 1.6.11
- 1.6.12
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.0.10
- 2.0.11
- 2.0.12
- 2.0.13
- 2.0.14
- 2.0.15
- 2.0.16
- 2.0.17
- 2.5.0
- 2.5.1
- 2.5.2
- 2.5.3
- 2.5.4
- 2.5.5
- 2.5.6
- 2.5.7
- 2.6.0
- 2.6.1
- 2.6.2
- 2.6.3
- 2.6.4
- 2.6.5
- 2.6.6
- 2.6.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://dl.packetstormsecurity.net/1009-exploits/phpmyfaq268-xss.txt x_refsource_MISCExploit
- http://seclists.org/bugtraq/2010/Sep/207 mailing-listx_refsource_BUGTRAQExploit
- http://secunia.com/advisories/41625 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.openwall.com/lists/oss-security/2012/03/08/2 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/03/08/7 mailing-listx_refsource_MLIST
- http://www.osvdb.org/68268 vdb-entryx_refsource_OSVDB
- http://www.phpmyfaq.de/advisory_2010-09-28.php x_refsource_CONFIRMVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62092 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://dl.packetstormsecurity.net/1009-exploits/phpmyfaq268-xss.txt | x_refsource_MISCExploit | |
| http://seclists.org/bugtraq/2010/Sep/207 | mailing-listx_refsource_BUGTRAQExploit | |
| http://secunia.com/advisories/41625 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.openwall.com/lists/oss-security/2012/03/08/2 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2012/03/08/7 | mailing-listx_refsource_MLIST | |
| http://www.osvdb.org/68268 | vdb-entryx_refsource_OSVDB | |
| http://www.phpmyfaq.de/advisory_2010-09-28.php | x_refsource_CONFIRMVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/62092 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 22, 2012
Updated Aug 7, 2024
Reserved Aug 19, 2011
Link CVE-2010-4821
CISA Vulnrichment
Updated n/a