CVE-2010-3931
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04…
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- rocomotion/p board · rocomotion/p diary r · rocomotion/p forum · rocomotion/p link · rocomotion/p link compact · rocomotion/p up board · rocomotion/pm bbs · rocomotion/pm forum · rocomotion/pplog · rocomotion/pplog 2
- Source
- vultures@jpcert.or.jp
References
- http://another.rocomotion.jp/12949466953653.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN09115481/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000006.htmlThird Party Advisory
- http://osvdb.org/70495Broken Link
- http://secunia.com/advisories/42957Broken Link
- http://www.securityfocus.com/bid/45838Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64745Third Party Advisory, VDB Entry
- http://another.rocomotion.jp/12949466953653.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN09115481/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000006.htmlThird Party Advisory
- http://osvdb.org/70495Broken Link
- http://secunia.com/advisories/42957Broken Link
- http://www.securityfocus.com/bid/45838Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64745Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.