fkie_cve-2010-1195
Vulnerability from fkie_nvd
Published
2010-03-31 18:00
Modified
2025-04-11 00:51
Severity ?
Summary
Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI.
References
Impacted products
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.0:*:*:*:*:*:*:*", "matchCriteriaId": "196439CC-B5BE-4016-B6CF-B8308002D61E", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.1:*:*:*:*:*:*:*", "matchCriteriaId": "20FFAE6B-9EBD-461A-AF5C-BB00EA2A652F", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.2:*:*:*:*:*:*:*", "matchCriteriaId": "7C064545-5C87-4CC5-A9FA-379A9F4ED0A2", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.3:*:*:*:*:*:*:*", "matchCriteriaId": "729BA91F-625A-4734-814D-EADE78A42CEC", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.4:*:*:*:*:*:*:*", "matchCriteriaId": "025BA9CF-1F77-4BC1-A884-3E49B23BB668", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.5:*:*:*:*:*:*:*", "matchCriteriaId": "C3120790-F2E2-4780-8022-B88EB326C8EC", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.10:*:*:*:*:*:*:*", "matchCriteriaId": "350315D5-C124-430D-BD7C-9EE5C3F4D957", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.11:*:*:*:*:*:*:*", "matchCriteriaId": "8CA658C7-2D79-4A8D-977E-D7F4640CEAFF", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.12:*:*:*:*:*:*:*", "matchCriteriaId": "8892C63F-297A-4D7A-8F63-B15BAE578645", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.13:*:*:*:*:*:*:*", "matchCriteriaId": "0E83FBBB-0837-41EE-A56A-C837FAE6394C", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.14:*:*:*:*:*:*:*", "matchCriteriaId": "E14AF144-D023-4FF1-B6B6-FF3E74D61F8E", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.15:*:*:*:*:*:*:*", "matchCriteriaId": "2FDE3606-418B-4E76-97F8-655CE1679857", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.16:*:*:*:*:*:*:*", "matchCriteriaId": "0F6877A1-D793-48A7-9187-63EA568EC854", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.17:*:*:*:*:*:*:*", "matchCriteriaId": "739EB847-21B4-4728-9F38-3925893A37A1", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.18:*:*:*:*:*:*:*", "matchCriteriaId": "FA1630A6-8578-4B0A-9F12-549EE0C42E8B", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.19:*:*:*:*:*:*:*", "matchCriteriaId": "15FE7BEB-A9E9-476A-ABDF-663A8F69BA7B", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.20:*:*:*:*:*:*:*", "matchCriteriaId": "10E53E42-F691-4237-AAC1-A93E35EADD36", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.30:*:*:*:*:*:*:*", "matchCriteriaId": "6994F418-61A4-4CB5-94FA-C7DC7A31BBB5", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31:*:*:*:*:*:*:*", "matchCriteriaId": "356A3B66-637B-4429-A201-EAB0A8FD9DB5", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31.1:*:*:*:*:*:*:*", "matchCriteriaId": "11BC2505-E5EF-4CA4-B747-F74F20BFDCE5", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31.2:*:*:*:*:*:*:*", "matchCriteriaId": "6CDB27DC-1B2B-4893-AFC7-71535919567B", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31.3:*:*:*:*:*:*:*", "matchCriteriaId": "18275BA3-A5D0-410B-9D90-B8DBDB486849", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.40:*:*:*:*:*:*:*", "matchCriteriaId": "06E20D04-ADEA-4773-843A-2D6BB0FC5591", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.41:*:*:*:*:*:*:*", "matchCriteriaId": "C76D329C-975F-4180-9102-2CAA24230C6A", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.42:*:*:*:*:*:*:*", "matchCriteriaId": "86A6C38C-6B71-4A83-B280-C1195D668DDF", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.43:*:*:*:*:*:*:*", "matchCriteriaId": "0AB24A6A-D1D2-4200-ACF6-93F20AA2CEE2", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.44:*:*:*:*:*:*:*", "matchCriteriaId": "3B998D73-576D-4942-A164-8898437815DA", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.45:*:*:*:*:*:*:*", "matchCriteriaId": "69FBED8F-C567-4366-97E7-E5CF6A9BC479", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.46:*:*:*:*:*:*:*", "matchCriteriaId": "01494227-D431-4F2B-8174-25A5C2CBC3FB", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.47:*:*:*:*:*:*:*", "matchCriteriaId": "C26EFAF6-5DE3-4562-A831-DE9CCD40B31E", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.48:*:*:*:*:*:*:*", "matchCriteriaId": "553F2BF0-0375-406F-9F6D-33E49543BC4A", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.49:*:*:*:*:*:*:*", "matchCriteriaId": "06FBD3B4-99E3-4ED5-A49F-8747C26962BE", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.50:*:*:*:*:*:*:*", "matchCriteriaId": "4888637D-EBA4-4DD3-9EE9-ABA9D26799AD", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.51:*:*:*:*:*:*:*", "matchCriteriaId": "5B6F140A-2391-4663-B680-8E58FD315C4C", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.52:*:*:*:*:*:*:*", "matchCriteriaId": "29DF1E0B-250C-47C1-BC76-4F9EE90AB836", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.53:*:*:*:*:*:*:*", "matchCriteriaId": "82F41174-0E9C-4A09-BAEB-D75595181334", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.00:*:*:*:*:*:*:*", "matchCriteriaId": "02ADB4DC-4FA7-4696-BE15-4038AA7C8440", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.01:*:*:*:*:*:*:*", "matchCriteriaId": "CCA76343-5D08-4E79-8E83-29799E8BF9C6", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.02:*:*:*:*:*:*:*", "matchCriteriaId": "110383CC-7DAB-4FC7-9898-92AF1CB76585", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.03:*:*:*:*:*:*:*", "matchCriteriaId": "CB47B7AD-40A2-466F-AF26-92DB4BF9EDCB", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.04:*:*:*:*:*:*:*", "matchCriteriaId": "4560DD73-D1A2-46D9-A3F7-BAC5A294B91B", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.05:*:*:*:*:*:*:*", "matchCriteriaId": "E96286A8-66B5-4BB1-9458-2BD511FCF633", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.06:*:*:*:*:*:*:*", "matchCriteriaId": "27D8EE30-BFBB-45C6-8B27-012E17CA3C48", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.07:*:*:*:*:*:*:*", "matchCriteriaId": "7374FCDB-55E7-48AC-8E38-51C20500BBE6", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.08:*:*:*:*:*:*:*", "matchCriteriaId": "03FA5A43-6317-4510-BC00-7BCF3DB4F502", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.09:*:*:*:*:*:*:*", "matchCriteriaId": "695759BE-8539-496A-AABD-2F56ACFDA0FD", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.10:*:*:*:*:*:*:*", "matchCriteriaId": "0566B074-7F01-4482-8F26-F08EDD4F0B9A", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.11:*:*:*:*:*:*:*", "matchCriteriaId": "9A3D2C53-A15F-4FEF-A56B-A4A00C24DF39", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.12:*:*:*:*:*:*:*", "matchCriteriaId": "B8F89322-85B0-4C8B-AB60-4577FB914D4F", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.13:*:*:*:*:*:*:*", "matchCriteriaId": "5B55BCD8-E214-4C75-86F7-247ECBEAFF1B", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.14:*:*:*:*:*:*:*", "matchCriteriaId": "B19DCEDD-AC25-48F2-B0D9-F35C67AA3A24", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.141:*:*:*:*:*:*:*", "matchCriteriaId": "9DDE6204-5CC9-4867-BD9E-9C999C1E6D6F", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.1415:*:*:*:*:*:*:*", "matchCriteriaId": "29453740-F182-4BD1-ADD8-BF3F37D2D4DB", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.14159:*:*:*:*:*:*:*", "matchCriteriaId": "A6FA5E6A-F504-43DC-8021-1BE35FB25269", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.141592:*:*:*:*:*:*:*", "matchCriteriaId": "4278165A-A50E-4B8D-BB7C-FF9582FD5FCC", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.1415926:*:*:*:*:*:*:*", "matchCriteriaId": "0D3CC84E-2651-413A-A5EA-5F7B8FE52C94", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.14159265:*:*:*:*:*:*:*", "matchCriteriaId": "29520481-85F4-4A51-AF80-2F5043097985", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20091009:*:*:*:*:*:*:*", "matchCriteriaId": "3DAC672C-049F-44F3-BBEB-145CA43A71A0", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20091017:*:*:*:*:*:*:*", "matchCriteriaId": "9707D395-6C38-4AC4-9439-893F03EFB254", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20091022:*:*:*:*:*:*:*", "matchCriteriaId": "036BB985-A056-4567-BE9D-C2A7E5BC7A6B", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20091023:*:*:*:*:*:*:*", "matchCriteriaId": "DFF27ADD-874F-41A5-A26C-CAA239E4DB15", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20091031:*:*:*:*:*:*:*", "matchCriteriaId": "B31EC7C6-A717-406B-A1D0-9DB71D61F91C", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20091113:*:*:*:*:*:*:*", "matchCriteriaId": "8376C3F6-23D5-4190-B1C1-FC64E1E63BD6", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20091202:*:*:*:*:*:*:*", "matchCriteriaId": "5E355429-D88B-440C-AF37-70C68BDE5A1C", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20091218:*:*:*:*:*:*:*", "matchCriteriaId": "1BD3E355-A140-43E1-AEBA-EC2645EF5B3D", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20100102.3:*:*:*:*:*:*:*", "matchCriteriaId": "9E1DA17C-2992-4451-B3E0-589A0AF2DAE3", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20100122:*:*:*:*:*:*:*", "matchCriteriaId": "1722DF6B-0C2D-41BB-9232-A91FAD0ADBF8", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20100212:*:*:*:*:*:*:*", "matchCriteriaId": "94D0B8FC-8367-4701-BB4D-1AEF4AA09DEB", "vulnerable": true }, { "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.20100302:*:*:*:*:*:*:*", "matchCriteriaId": "49713406-54D0-48E9-A9C5-EE8934259B2C", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI." }, { "lang": "es", "value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el componente htmlscrubber en ikiwiki 2.x en versiones anteriores a la 2.53.5 y 3.x en versiones anteriores a la 3.20100312 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n mediante una URI data:image/svg+xml manipulada." } ], "id": "CVE-2010-1195", "lastModified": "2025-04-11T00:51:21.963", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ] }, "published": "2010-03-31T18:00:00.733", "references": [ { "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ], "url": "http://ikiwiki.info/security/#index36h2" }, { "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/38983" }, { "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/39048" }, { "source": "cve@mitre.org", "url": "http://www.debian.org/security/2010/dsa-2020" }, { "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2010/0662" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://ikiwiki.info/security/#index36h2" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/38983" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/39048" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.debian.org/security/2010/dsa-2020" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2010/0662" } ], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-79" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…