4.3
CVE-2010-4647
- EPSS 9.64%
- Veröffentlicht 13.01.2011 19:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eclipse ≫ Eclipse Ide Version <= 3.6.1
Eclipse ≫ Eclipse Ide Version1.0
Eclipse ≫ Eclipse Ide Version2.0
Eclipse ≫ Eclipse Ide Version2.0.1
Eclipse ≫ Eclipse Ide Version2.0.2
Eclipse ≫ Eclipse Ide Version2.1
Eclipse ≫ Eclipse Ide Version2.1.1
Eclipse ≫ Eclipse Ide Version2.1.2
Eclipse ≫ Eclipse Ide Version2.1.3
Eclipse ≫ Eclipse Ide Version3.0
Eclipse ≫ Eclipse Ide Version3.0.1
Eclipse ≫ Eclipse Ide Version3.0.2
Eclipse ≫ Eclipse Ide Version3.1
Eclipse ≫ Eclipse Ide Version3.1.1
Eclipse ≫ Eclipse Ide Version3.1.2
Eclipse ≫ Eclipse Ide Version3.2
Eclipse ≫ Eclipse Ide Version3.2.1
Eclipse ≫ Eclipse Ide Version3.2.2
Eclipse ≫ Eclipse Ide Version3.3
Eclipse ≫ Eclipse Ide Version3.3.1
Eclipse ≫ Eclipse Ide Version3.3.1.1
Eclipse ≫ Eclipse Ide Version3.3.2
Eclipse ≫ Eclipse Ide Version3.4
Eclipse ≫ Eclipse Ide Version3.4.1
Eclipse ≫ Eclipse Ide Version3.4.2
Eclipse ≫ Eclipse Ide Version3.5
Eclipse ≫ Eclipse Ide Version3.5.1
Eclipse ≫ Eclipse Ide Version3.5.2
Eclipse ≫ Eclipse Ide Version3.6 Updatem1
Eclipse ≫ Eclipse Ide Version3.6 Updatem2
Eclipse ≫ Eclipse Ide Version3.6 Updatem3
Eclipse ≫ Eclipse Ide Version3.6 Updatem4
Eclipse ≫ Eclipse Ide Version3.6 Updatem5
Eclipse ≫ Eclipse Ide Version3.6 Updatem6
Eclipse ≫ Eclipse Ide Version3.6 Updatem7
Eclipse ≫ Eclipse Ide Version3.6 Updaterc1
Eclipse ≫ Eclipse Ide Version3.6 Updaterc2
Eclipse ≫ Eclipse Ide Version3.6 Updaterc3
Eclipse ≫ Eclipse Ide Version3.6 Updaterc4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 9.64% | 0.926 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.