CVE-2010-2103
Last modified
CVE-2010-2103 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.. EPSS estimates a 34.93% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Axis2 | 1.4.1 |
| Apache | Axis2 | 1.5.1 |
References
- http://osvdb.org/64844Exploit
- http://secunia.com/advisories/39906Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1215Vendor Advisory
- http://osvdb.org/64844Exploit
- http://secunia.com/advisories/39906Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1215Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-2103?
How severe is CVE-2010-2103?
How do I fix CVE-2010-2103?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-2097The (1) iconv_mime_decode, (2) iconv_substr, and (3) iconv_m…
- CVE-2010-2098Incomplete blacklist vulnerability in usersettings.php in e1…
- CVE-2010-2099bbcode/php.bb in e107 0.7.20 and earlier does not perform ac…
- CVE-2010-2100The (1) htmlentities, (2) htmlspecialchars, (3) str_getcsv, …
- CVE-2010-2101The (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap,…
- CVE-2010-2102Buffer overflow in Webby Webserver 1.01 allows remote attack…
- CVE-2010-2104Directory traversal vulnerability in Orbit Downloader 3.0.0.…
- CVE-2010-2105Google Chrome before 5.0.375.55 does not properly follow the…
- CVE-2010-2106Unspecified vulnerability in Google Chrome before 5.0.375.55…
- CVE-2010-2107Unspecified vulnerability in Google Chrome before 5.0.375.55…
- CVE-2010-2108Unspecified vulnerability in Google Chrome before 5.0.375.55…
- CVE-2010-2109Unspecified vulnerability in Google Chrome before 5.0.375.55…
Are you affected by CVE-2010-2103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
