VulnerabilityModified
CVE-2010-1091
Multiple cross-site scripting (XSS) vulnerabilities in contact.php in phpMySite allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message parameters.
MEDIUM 4.3EPSS 1.47%
Does this matter?
Lower severity and a low EPSS score (1.47%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in contact.php in phpMySite allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message parameters.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.47% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- phpmysite/phpmysite
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/1002-exploits/phpmysite-sqlxss.txtExploit
- http://www.exploit-db.com/exploits/11588Exploit
- http://www.vupen.com/english/advisories/2010/0492Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56574
- http://packetstormsecurity.org/1002-exploits/phpmysite-sqlxss.txtExploit
- http://www.exploit-db.com/exploits/11588Exploit
- http://www.vupen.com/english/advisories/2010/0492Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56574
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.