CVE-2010-3931
Last modified
CVE-2010-3931 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.. EPSS estimates a 1.52% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rocomotion | P Board | <= 1.18 |
| Rocomotion | P Diary R | <= 1.13 |
| Rocomotion | P Forum | <= 1.30 |
| Rocomotion | P Link | <= 1.11 |
| Rocomotion | P Link Compact | <= 1.04 |
| Rocomotion | P Up Board | <= 1.38 |
| Rocomotion | Pm Bbs | <= 1.07 |
| Rocomotion | Pm Forum | <= 1.18 |
| Rocomotion | Pplog | <= 3.31 |
| Rocomotion | Pplog 2 | <= 3.37 |
References
- http://another.rocomotion.jp/12949466953653.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN09115481/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000006.htmlThird Party Advisory
- http://osvdb.org/70495Broken Link
- http://secunia.com/advisories/42957Broken Link
- http://www.securityfocus.com/bid/45838Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64745Third Party Advisory, VDB Entry
- http://another.rocomotion.jp/12949466953653.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN09115481/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000006.htmlThird Party Advisory
- http://osvdb.org/70495Broken Link
- http://secunia.com/advisories/42957Broken Link
- http://www.securityfocus.com/bid/45838Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64745Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3931?
How severe is CVE-2010-3931?
How do I fix CVE-2010-3931?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3925Contents-Mall before 15 does not properly handle passwords, …
- CVE-2010-3926Multiple cross-site scripting (XSS) vulnerabilities in Shop.…
- CVE-2010-3927Untrusted search path vulnerability in Lunascape before 6.4.…
- CVE-2010-3928Ruby Version Manager (RVM) before 1.2.1 writes file contents…
- CVE-2010-3929SQL injection vulnerability in MODx Evolution 1.0.4 and earl…
- CVE-2010-3930Directory traversal vulnerability in MODx Evolution 1.0.4 an…
- CVE-2010-3932Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2010-3933Ruby on Rails 2.3.9 and 3.0.0 does not properly handle neste…
- CVE-2010-3934The browser in Research In Motion (RIM) BlackBerry Device So…
- CVE-2010-3935Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2010-3936Cross-site scripting (XSS) vulnerability in Signurl.asp in M…
- CVE-2010-3937Microsoft Exchange Server 2007 SP2 on the x64 platform allow…
Are you affected by CVE-2010-3931?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
