Vulnerability Description
Emweb Wt before 3.1.1 does not validate the UTF-8 encoding of (1) form values and (2) JSignal arguments, which has unspecified impact and remote attack vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emweb | Wt | <= 3.1.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/38759Vendor Advisory
- http://www.osvdb.org/62717
- http://www.securityfocus.com/bid/38541
- http://www.webtoolkit.eu/wt/doc/reference/html/Releasenotes.htmlPatch
- http://secunia.com/advisories/38759Vendor Advisory
- http://www.osvdb.org/62717
- http://www.securityfocus.com/bid/38541
- http://www.webtoolkit.eu/wt/doc/reference/html/Releasenotes.htmlPatch
FAQ
What is CVE-2010-1273?
CVE-2010-1273 is a vulnerability with a CVSS score of 9.3 (HIGH). Emweb Wt before 3.1.1 does not validate the UTF-8 encoding of (1) form values and (2) JSignal arguments, which has unspecified impact and remote attack vectors.
How severe is CVE-2010-1273?
CVE-2010-1273 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-1273?
Check the references section above for vendor advisories and patch information. Affected products include: Emweb Wt.