CVE-2010-4355

Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2, when the insert or edit feature is enabled, allows remote authenticated users to inject arbitrary web script or HTML via the select_single parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
VendorProductVersion
dadabikdadabik
𝑥
≤ 4.3
dadabikdadabik
1.0:beta
dadabikdadabik
1.0.1:beta
dadabikdadabik
1.0.2:beta
dadabikdadabik
1.0.3:beta
dadabikdadabik
1.0.4:beta
dadabikdadabik
1.0.5:beta
dadabikdadabik
1.1:beta
dadabikdadabik
1.5
dadabikdadabik
1.5b:b
dadabikdadabik
1.6
dadabikdadabik
1.7
dadabikdadabik
1.8
dadabikdadabik
1.9
dadabikdadabik
1.9.1
dadabikdadabik
2.0:beta
dadabikdadabik
2.0.1:beta
dadabikdadabik
2.1:beta
dadabikdadabik
2.1b:b
dadabikdadabik
2.2:beta
dadabikdadabik
2.2.1
dadabikdadabik
2.2.1:beta
dadabikdadabik
3.0
dadabikdadabik
3.0:beta
dadabikdadabik
3.1:beta
dadabikdadabik
3.2
dadabikdadabik
3.2:beta
dadabikdadabik
4.0
dadabikdadabik
4.0:alpha
dadabikdadabik
4.0:beta
dadabikdadabik
4.0:beta2
dadabikdadabik
4.1
dadabikdadabik
4.1:beta
dadabikdadabik
4.1:rc1
dadabikdadabik
4.1:rc2
dadabikdadabik
4.1:rc3
dadabikdadabik
4.2
dadabikdadabik
4.2:beta
dadabikdadabik
4.3:alpha
dadabikdadabik
4.3:beta
dadabikdadabik
4.3:beta2
𝑥
= Vulnerable software versions