CVE-2010-4569
published 2011-01-28CVE-2010-4569: Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.72%
75.1th percentile
Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the real name field of a user account, related to the AutoComplete widget in YUI.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| yahoo | yui | <= 2.8.2 | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6546-f3c3-rp4g: Cross-site scripting (XSS) vulnerability in Bugzilla 3
ghsa_unreviewed·2022-05-17
CVE-2010-4569 [MEDIUM] CWE-79 GHSA-6546-f3c3-rp4g: Cross-site scripting (XSS) vulnerability in Bugzilla 3
Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the real name field of a user account, related to the AutoComplete widget in YUI.
GHSA
GHSA-qv3f-mvrx-9wqv: Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-4710 [MEDIUM] CWE-79 GHSA-qv3f-mvrx-9wqv: Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2
Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570.
No detection rules found.
No public exploits indexed.
http://osvdb.org/70701http://www.bugzilla.org/security/3.2.9/http://www.securityfocus.com/bid/45982http://www.vupen.com/english/advisories/2011/0207http://www.vupen.com/english/advisories/2011/0271http://yuilibrary.com/forum/viewtopic.php?p=12923http://yuilibrary.com/projects/yui2/ticket/2529228https://bugzilla.mozilla.org/show_bug.cgi?id=619637https://exchange.xforce.ibmcloud.com/vulnerabilities/65178http://osvdb.org/70701http://www.bugzilla.org/security/3.2.9/http://www.securityfocus.com/bid/45982http://www.vupen.com/english/advisories/2011/0207http://www.vupen.com/english/advisories/2011/0271http://yuilibrary.com/forum/viewtopic.php?p=12923http://yuilibrary.com/projects/yui2/ticket/2529228https://bugzilla.mozilla.org/show_bug.cgi?id=619637https://exchange.xforce.ibmcloud.com/vulnerabilities/65178
2011-01-28
Published