CVE-2010-1995 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users with \Add new article\ privileges to inject arbitrary web script or HTML via the (1) title (2) subTitle and (3) author parameters in conjunction with a /admin/news/article/add PATH_INFO.
Reference
http://holisticinfosec.org/content/view/141/45/ http://osvdb.org/64550 http://secunia.com/advisories/39320 http://secunia.com/secunia_research/2010-59/ http://www.securityfocus.com/archive/1/511272/100/0/threaded http://www.securityfocus.com/bid/40108 https://exchange.xforce.ibmcloud.com/vulnerabilities/58471
Share on: