CVE-2010-3447

Cross-site scripting (XSS) vulnerability in view.php in the file viewer in Horde Gollem before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the file parameter in a view_file action.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
hordegollem
𝑥
≤ 1.1.1
hordegollem
1.0
hordegollem
1.0:alpha
hordegollem
1.0:beta
hordegollem
1.0:rc1
hordegollem
1.0:rc2
hordegollem
1.0.1
hordegollem
1.0.1:rc1
hordegollem
1.0.2
hordegollem
1.0.2:rc1
hordegollem
1.0.3
hordegollem
1.0.4
hordegollem
1.1
hordegollem
1.1:rc1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gollem
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
raring
dne
quantal
dne
precise
ignored
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
karmic
ignored
hardy
ignored
dapper
ignored
References