Multiple cross-site scripting (XSS) vulnerabilities in odCMS 1.06, and possibly...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in odCMS 1.06, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Page parameter to (1) _main/index.php, (2) _members/index.php, (3) _forum/index.php, (4) _docs/index.php, and (5) _announcements/index.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-2344
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/39942
- http://www.osvdb.org/65259
- http://www.osvdb.org/65258
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59247
- http://www.osvdb.org/65260
- http://www.securityfocus.com/bid/40678
- http://www.osvdb.org/65262
- http://holisticinfosec.org/content/view/146/45/
- http://www.osvdb.org/65261
Affected Vendor
odcms
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.