CVE-2010-2152
Last modified
CVE-2010-2152 is a vulnerability of currently unknown severity. Unspecified vulnerability in JustSystems Ichitaro 2004 through 2009, Ichitaro Government 2006 through 2009, and Just School 2008 and 2009 allows remote attackers to execute arbitrary code via unknown vectors related to "product character attribute processing" for a document.. EPSS estimates a 5.56% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in JustSystems Ichitaro 2004 through 2009, Ichitaro Government 2006 through 2009, and Just School 2008 and 2009 allows remote attackers to execute arbitrary code via unknown vectors related to "product character attribute processing" for a document.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Justsystems | Ichitaro | 2004 |
| Justsystems | Ichitaro | 2005 |
| Justsystems | Ichitaro | 2006 |
| Justsystems | Ichitaro | 2007 |
| Justsystems | Ichitaro | 2008 |
| Justsystems | Ichitaro | 2009 |
| Justsystems | Just School | 2008 |
| Justsystems | Just School | 2009 |
References
- http://secunia.com/advisories/40008Vendor Advisory
- http://www.justsystems.com/jp/info/js10002.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1283Vendor Advisory
- http://secunia.com/advisories/40008Vendor Advisory
- http://www.justsystems.com/jp/info/js10002.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1283Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-2152?
How severe is CVE-2010-2152?
How do I fix CVE-2010-2152?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-2146PHP remote file inclusion vulnerability in banned.php in Vis…
- CVE-2010-2147Cross-site scripting (XSS) vulnerability in the My Car (com_…
- CVE-2010-2148SQL injection vulnerability in the My Car (com_mycar) compon…
- CVE-2010-2149Session fixation vulnerability in Fujitsu e-Pares V01 L01, L…
- CVE-2010-2150Cross-site scripting (XSS) vulnerability Fujitsu e-Pares V01…
- CVE-2010-2151Cross-site request forgery (CSRF) vulnerability in Fujitsu e…
- CVE-2010-2153Unrestricted file upload vulnerability in admin/code/tce_fun…
- CVE-2010-2154Cross-site scripting (XSS) vulnerability in the Search Site …
- CVE-2010-2155Multiple cross-site scripting (XSS) vulnerabilities in zc/pu…
- CVE-2010-2156ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows …
- CVE-2010-2157Unspecified vulnerability in CA ARCserve Backup r11.5 SP4, r…
- CVE-2010-2158Multiple cross-site scripting (XSS) vulnerabilities in the S…
Are you affected by CVE-2010-2152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
