CVE-2010-0132

Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to "search_re input," a different vulnerability than CVE-2010-0736.
Cross-site Scripting
Severity
UNKNOWN
AV:N/AC:H/Au:N/C:N/I:P/A:N
Atk. Vector
NETWORK
Atk. Complexity
HIGH
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
viewvcviewvc
1.0.0
viewvcviewvc
1.0.1
viewvcviewvc
1.0.2
viewvcviewvc
1.0.3
viewvcviewvc
1.0.4
viewvcviewvc
1.0.5
viewvcviewvc
1.0.6
viewvcviewvc
1.0.7
viewvcviewvc
1.0.8
viewvcviewvc
1.0.9
viewvcviewvc
1.0.10
viewvcviewvc
1.1.0
viewvcviewvc
1.1.1
viewvcviewvc
1.1.2
viewvcviewvc
1.1.3
viewvcviewvc
1.1.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
viewvc
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
ignored
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
dne