Back to Database
Status published
Medium
CVE-2010-2491
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-2491
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/048221.html
- http://sourceforge.net/mailarchive/message.php?msg_name=AANLkTimIYtyRzTAReGmTSCEqPYBvwkkxrP6YKrdVm_nU%40mail.gmail.com
- http://bugs.gentoo.org/show_bug.cgi?id=326395
- http://secunia.com/advisories/41585
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/048061.html
- http://issues.roundup-tracker.org/issue2550654
- https://bugzilla.redhat.com/show_bug.cgi?id=610861
- http://www.openwall.com/lists/oss-security/2010/07/02/3
- http://secunia.com/advisories/40433
- http://www.securityfocus.com/bid/41326
- http://www.openwall.com/lists/oss-security/2010/07/02/12
- http://roundup.svn.sourceforge.net/viewvc/roundup/roundup/trunk/roundup/cgi/client.py?r1=4486&r2=4485&pathrev=4486
- http://roundup.svn.sourceforge.net/viewvc/roundup?view=revision&revision=4486
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/048018.html
More from roundup-tracker
View All →CVE-2025-53865
In Roundup before 2.5.0, XSS can occur via interaction between...
Medium
6.4
CVE-2014-6276
schema.py in Roundup before 1.5.1 does not properly limit attributes...
Medium
4.3
CVE-2012-6132
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote...
Medium
4.3
CVE-2012-6131
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20...
Medium
4.3
CVE-2012-6130
Cross-site scripting (XSS) vulnerability in the history display in Roundup...
Medium
4.3
Affected Vendor
roundup-tracker
View all reports →Affected Software
roundup
Vulnerable Versions:
0, 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.2.0, 0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.2.6, 0.2.7, 0.2.8, 0.3.0, 0.4.0, 0.4.1, 0.4.2, 0.5, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7, 0.5.8, 0.5.9, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.6.5, 0.6.6, 0.6.7, 0.6.8, 0.6.9, 0.6.10, 0.6.11, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.7.7, 0.7.8, 0.7.9, 0.7.10, 0.7.11, 0.7.12, 0.8.0, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.8.6, 0.9.0, 1.0, 1.0.1, 1.1.0, 1.1.1, 1.1.2, 1.2.0, 1.2.1, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9, 1.4.10, 1.4.11, 1.4.12
Timeline
Official Publish:
September 24th, 2010
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.