Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the bug_id parameter to edit_comment.aspx, (3) the id parameter to edit_user_permissions2.aspx, or (4) the default_name parameter to edit_customfield.aspx. NOTE: some of these details are obtained from third party information.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ifdefined | Bugtracker.Net | <= 3.4.4 |
Related Weaknesses (CWE)
References
- http://btnet.svn.sourceforge.net/viewvc/btnet/RELEASE_NOTES.TXT?revision=578&vie
- http://secunia.com/advisories/42418Vendor Advisory
- http://www.coresecurity.com/content/multiple-vulnerabilities-in-bugtrackerExploit
- http://www.exploit-db.com/exploits/15653Exploit
- http://www.securityfocus.com/archive/1/514957/100/0/threaded
- http://www.securityfocus.com/bid/45121
- http://btnet.svn.sourceforge.net/viewvc/btnet/RELEASE_NOTES.TXT?revision=578&vie
- http://secunia.com/advisories/42418Vendor Advisory
- http://www.coresecurity.com/content/multiple-vulnerabilities-in-bugtrackerExploit
- http://www.exploit-db.com/exploits/15653Exploit
- http://www.securityfocus.com/archive/1/514957/100/0/threaded
- http://www.securityfocus.com/bid/45121
FAQ
What is CVE-2010-3266?
CVE-2010-3266 is a vulnerability with a CVSS score of 3.5 (LOW). Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (...
How severe is CVE-2010-3266?
CVE-2010-3266 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3266?
Check the references section above for vendor advisories and patch information. Affected products include: Ifdefined Bugtracker.Net.