VulnerabilityModified
CVE-2010-2256
Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to…
MEDIUM 4.3EPSS 1.45%
Does this matter?
Lower severity and a low EPSS score (1.45%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.45% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- payperviewvideosoftware/pay per minute video chat script
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/1001-exploits/ppmvcs-sqlxss.txtExploit
- http://secunia.com/advisories/38086Vendor Advisory
- http://www.exploit-db.com/exploits/10983Exploit
- http://packetstormsecurity.org/1001-exploits/ppmvcs-sqlxss.txtExploit
- http://secunia.com/advisories/38086Vendor Advisory
- http://www.exploit-db.com/exploits/10983Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.