CVE-2010-2277
published 2010-06-15CVE-2010-2277: Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.22%
65.3th percentile
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | lotus_connections | — | — |
| ibm | lotus_connections | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5vpg-7cf5-grcm: Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2
ghsa_unreviewed·2022-05-17
CVE-2010-2277 [MEDIUM] CWE-79 GHSA-5vpg-7cf5-grcm: Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.
VMware
VMware products address vulnerabilities in WebAccess
vendor_vmware·2010-03-29·CVSS 4.3
CVE-2009-2277 [MEDIUM] VMware products address vulnerabilities in WebAccess
VMSA-2010-0005: VMware products address vulnerabilities in WebAccess
a. WebAccess Context Data Cross-site Scripting Vulnerability A cross-site scripting vulnerability in WebAccess allows for disclosure of sensitive information. The flaw is due to insufficient verification of certain parameters which may lead to redirection of a user's requests. This vulnerability can only be exploited if the attacker tricks the WebAccess user into clicking a malicious link and the attacker has control of a server on the same network as the system where WebAccess is being used.
CVEs: CVE-2009-2277, CVE-2010-0686, CVE-2010-1137, CVE-2010-1193
Affected products: ESXi, VMware Workstation
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/40007http://www-01.ibm.com/support/docview.wss?uid=swg21431472http://www-1.ibm.com/support/docview.wss?uid=swg1LO47214http://www-1.ibm.com/support/docview.wss?uid=swg1LO47362http://www-1.ibm.com/support/docview.wss?uid=swg1LO47921http://www.vupen.com/english/advisories/2010/1281http://secunia.com/advisories/40007http://www-01.ibm.com/support/docview.wss?uid=swg21431472http://www-1.ibm.com/support/docview.wss?uid=swg1LO47214http://www-1.ibm.com/support/docview.wss?uid=swg1LO47362http://www-1.ibm.com/support/docview.wss?uid=swg1LO47921http://www.vupen.com/english/advisories/2010/1281
2010-06-15
Published