CVE-2010-2256
Last modified
CVE-2010-2256 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php.. EPSS estimates a 1.45% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Payperviewvideosoftware | Pay Per Minute Video Chat Script | 2.0 |
| Payperviewvideosoftware | Pay Per Minute Video Chat Script | 2.1 |
References
- http://secunia.com/advisories/38086Vendor Advisory
- http://secunia.com/advisories/38086Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-2256?
How severe is CVE-2010-2256?
How do I fix CVE-2010-2256?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-2250Drupal 5.x and 6.x before 6.16 uses a user-supplied value in…6.1
- CVE-2010-2251The get1 command, as used by lftpget, in LFTP before 4.0.6 d…
- CVE-2010-2252GNU Wget 1.12 and earlier uses a server-provided filename in…
- CVE-2010-2253lwp-download in libwww-perl before 5.835 does not reject dow…
- CVE-2010-2254SQL injection vulnerability in the Shape5 Bridge of Hope tem…
- CVE-2010-2255SQL injection vulnerability in the BF Survey Pro (com_bfsurv…
- CVE-2010-2257SQL injection vulnerability in index_ie.php in Pay Per Minut…
- CVE-2010-2258Cross-site scripting (XSS) vulnerability in signupconfirm.ph…
- CVE-2010-2259Directory traversal vulnerability in the BF Survey (com_bfsu…
- CVE-2010-2260Multiple cross-site scripting (XSS) vulnerabilities in Gambi…
- CVE-2010-2261Linksys WAP54Gv3 firmware 3.04.03 and earlier allows remote …
- CVE-2010-2262Galileo Students Team Weborf before 0.12.1 allows remote att…
Are you affected by CVE-2010-2256?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
