CVE-2010-2086
published 2010-05-27CVE-2010-2086: Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which…
PriorityP417medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.12%
79.7th percentile
Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | myfaces | — | — |
| apache | myfaces | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache MyFaces Cross-site Scripting vulnerability
ghsa·2022-05-17
CVE-2010-2086 [MEDIUM] CWE-79 Apache MyFaces Cross-site Scripting vulnerability
Apache MyFaces Cross-site Scripting vulnerability
Apache MyFaces 1.1.7 and 1.2.8 (All previous versions are likely vulnerable), as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
OSV
Apache MyFaces Cross-site Scripting vulnerability
osv·2022-05-17
CVE-2010-2086 [MEDIUM] Apache MyFaces Cross-site Scripting vulnerability
Apache MyFaces Cross-site Scripting vulnerability
Apache MyFaces 1.1.7 and 1.2.8 (All previous versions are likely vulnerable), as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
Red Hat
MyFaces: XSS via state view
vendor_redhat·2010-02-08·CVSS 4.0
CVE-2010-2086 [MEDIUM] CWE-79 MyFaces: XSS via state view
MyFaces: XSS via state view
Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
JBoss Enterprise Web Server 1.0.0 ships with Apache MyFaces 1.1.0. Apache MyFaces 1.1.0 does not support encrypted
view state. When the application's view state is not encrypted, it is possible for an attacker to supply a new or modified view object as part of a request. This allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that i
No detection rules found.
Exploit-DB
phpBB - 'viewtopic.php' Arbitrary Code Execution (Metasploit)
exploitdb·2010-07-03
CVE-2005-2086 phpBB - 'viewtopic.php' Arbitrary Code Execution (Metasploit)
phpBB - 'viewtopic.php' Arbitrary Code Execution (Metasploit)
---
##
# $Id: phpbb_highlight.rb 9671 2010-07-03 06:21:31Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'phpBB viewtopic.php Arbitrary Code Execution',
'Description' => %q{
This module exploits two arbitrary PHP code execution flaws in the
phpBB forum system. The problem is that the 'highlight' parameter
in the 'viewtopic.php' script is not verified properly and will
allow an attacker to inject arbitrary code via preg_replace().
This vulnerability was introduced in rev
Exploit-DB
Juniper SSL-VPN IVE - 'JuniperSetupDLL.dll' ActiveX Control Buffer Overflow (Metasploit)
exploitdb·2010-05-09
CVE-2006-2086 Juniper SSL-VPN IVE - 'JuniperSetupDLL.dll' ActiveX Control Buffer Overflow (Metasploit)
Juniper SSL-VPN IVE - 'JuniperSetupDLL.dll' ActiveX Control Buffer Overflow (Metasploit)
---
##
# $Id: juniper_sslvpn_ive_setupdll.rb 9262 2010-05-09 17:45:00Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Juniper SSL-VPN IVE JuniperSetupDLL.dll ActiveX Control Buffer Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in the JuniperSetupDLL.dll
library which is called by the JuniperSetup.ocx ActiveX control,
as part of the Juniper SSL-VPN (IVE) appliance. By specifying an
overly long string to the Produc
Exploit-DB
Sambar Server 6 - Search Results Buffer Overflow (Metasploit)
exploitdb·2010-02-13
CVE-2004-2086 Sambar Server 6 - Search Results Buffer Overflow (Metasploit)
Sambar Server 6 - Search Results Buffer Overflow (Metasploit)
---
##
# $Id: sambar6_search_results.rb 8480 2010-02-13 20:15:19Z patrickw $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Sambar 6 Search Results Buffer Overflow',
'Description' => %q{
This module exploits a buffer overflow found in the
/search/results.stm application that comes with Sambar 6.
This code is a direct port of Andrew Griffiths's SMUDGE
exploit, the only changes made were to the nops and payload.
This exploit causes the service to die, whether you provided
the cor
http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdfhttps://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txthttp://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdfhttps://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt
2010-05-27
Published