CVE-2010-3266

UnknownEPSS 2.80%

Last modified

CVE-2010-3266 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the bug_id parameter to edit_comment.aspx, (3) the id parameter to edit_user_permissions2.aspx, or (4) the default_name parameter to edit_customfield.aspx. NOTE: some of these details are obtained from third party information.. EPSS estimates a 2.80% chance of exploitation in the next 30 days.

Description

Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the bug_id parameter to edit_comment.aspx, (3) the id parameter to edit_user_permissions2.aspx, or (4) the default_name parameter to edit_customfield.aspx. NOTE: some of these details are obtained from third party information.

Metrics

EPSS Probability
2.80%

84.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IfdefinedBugtracker.Net<= 3.4.4
IfdefinedBugtracker.Net0.91
IfdefinedBugtracker.Net2.4.1
IfdefinedBugtracker.Net2.4.2
IfdefinedBugtracker.Net2.4.3
IfdefinedBugtracker.Net2.4.4
IfdefinedBugtracker.Net2.4.5
IfdefinedBugtracker.Net2.4.6
IfdefinedBugtracker.Net2.4.7
IfdefinedBugtracker.Net2.4.8
IfdefinedBugtracker.Net2.5.0
IfdefinedBugtracker.Net2.5.1
IfdefinedBugtracker.Net2.5.2
IfdefinedBugtracker.Net2.5.3
IfdefinedBugtracker.Net2.5.4
IfdefinedBugtracker.Net2.5.5
IfdefinedBugtracker.Net2.5.6
IfdefinedBugtracker.Net2.5.7
IfdefinedBugtracker.Net2.5.8
IfdefinedBugtracker.Net2.5.9
IfdefinedBugtracker.Net2.6.0
IfdefinedBugtracker.Net2.6.1
IfdefinedBugtracker.Net2.6.2
IfdefinedBugtracker.Net2.6.3
IfdefinedBugtracker.Net2.6.4
IfdefinedBugtracker.Net2.6.5
IfdefinedBugtracker.Net2.6.6
IfdefinedBugtracker.Net2.6.7
IfdefinedBugtracker.Net2.6.8
IfdefinedBugtracker.Net2.6.9
IfdefinedBugtracker.Net2.7.0
IfdefinedBugtracker.Net2.7.1
IfdefinedBugtracker.Net2.7.2
IfdefinedBugtracker.Net2.7.3
IfdefinedBugtracker.Net2.7.4
IfdefinedBugtracker.Net2.7.5
IfdefinedBugtracker.Net2.7.6
IfdefinedBugtracker.Net2.7.7
IfdefinedBugtracker.Net2.7.8
IfdefinedBugtracker.Net2.7.9
IfdefinedBugtracker.Net2.8.0
IfdefinedBugtracker.Net2.8.1
IfdefinedBugtracker.Net2.8.2
IfdefinedBugtracker.Net2.8.3
IfdefinedBugtracker.Net2.8.4
IfdefinedBugtracker.Net2.8.5
IfdefinedBugtracker.Net2.8.6
IfdefinedBugtracker.Net2.8.7
IfdefinedBugtracker.Net2.8.8
IfdefinedBugtracker.Net2.8.9

Showing 50 of 85 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-3266?
Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the bug_id parameter to edit_comment.aspx, (3) the id parameter to edit_user_permissions2.aspx, or (4) the default_name parameter to edit_customfield.aspx. NOTE: some of these details are obtained from third party information.
How severe is CVE-2010-3266?
Severity scoring for CVE-2010-3266 is pending analysis. The EPSS model estimates a 2.80% probability of exploitation in the next 30 days.
How do I fix CVE-2010-3266?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-3266?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST