CVE-2010-4570
published 2011-01-28CVE-2010-4570: Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.74%
75.3th percentile
Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the summary field, related to the DataTable widget in YUI.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| yahoo | yui | <= 2.8.2 | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4mw2-9w62-mvpx: Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3
ghsa_unreviewed·2022-05-17
CVE-2010-4570 [MEDIUM] CWE-79 GHSA-4mw2-9w62-mvpx: Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3
Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the summary field, related to the DataTable widget in YUI.
GHSA
GHSA-qv3f-mvrx-9wqv: Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-4710 [MEDIUM] CWE-79 GHSA-qv3f-mvrx-9wqv: Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2
Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570.
No detection rules found.
No public exploits indexed.
http://osvdb.org/70702http://www.bugzilla.org/security/3.2.9/http://www.securityfocus.com/bid/45982http://www.vupen.com/english/advisories/2011/0207http://www.vupen.com/english/advisories/2011/0271http://yuilibrary.com/forum/viewtopic.php?p=12923http://yuilibrary.com/projects/yui2/ticket/2529228https://bugzilla.mozilla.org/show_bug.cgi?id=619648https://exchange.xforce.ibmcloud.com/vulnerabilities/65179http://osvdb.org/70702http://www.bugzilla.org/security/3.2.9/http://www.securityfocus.com/bid/45982http://www.vupen.com/english/advisories/2011/0207http://www.vupen.com/english/advisories/2011/0271http://yuilibrary.com/forum/viewtopic.php?p=12923http://yuilibrary.com/projects/yui2/ticket/2529228https://bugzilla.mozilla.org/show_bug.cgi?id=619648https://exchange.xforce.ibmcloud.com/vulnerabilities/65179
2011-01-28
Published