CVE-2010-3931
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Affected (10)
Products: Rocomotion: P Board, P Diary R, P Forum, P Link, P Link Compact, P Up Board, Pm Bbs, Pm Forum, Pplog, Pplog 2
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.18 | |
| Up to 1.13 | |
| Up to 1.30 | |
| Up to 1.11 | |
| Up to 1.04 | |
| Up to 1.38 | |
| Up to 1.07 | |
| Up to 1.18 | |
| Up to 3.31 | |
| Up to 3.37 |
References (14)
Source: vultures@jpcert.or.jp
Third Party Advisory
Source: vultures@jpcert.or.jp
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.