CVE-2010-4875
Vodpod Video Gallery <= 3.1.7 - Reflected Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en vodpod-video-gallery/vodpod_gallery_thumbs.php en el Plugin Vodpod Video Gallery v3.1.5 para WordPress, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro gid.
Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-11-05 CVE Published
- 2010-11-08 First Exploit
- 2011-10-07 CVE Reserved
- 2023-10-26 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/8431 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/63057 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/34976 | 2010-11-08 | |
http://osvdb.org/69084 | 2024-08-07 | |
http://packetstormsecurity.org/1011-exploits/wpvodpod-xss.txt | 2024-08-07 | |
http://www.johnleitch.net/Vulnerabilities/WordPress.Vodpod.Video.Gallery.3.1.5.Reflected.Cross-site.Scripting/58 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/42195 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xondie Search vendor "Xondie" | Vodpod Video Gallery Search vendor "Xondie" for product "Vodpod Video Gallery" | 3.1.5 Search vendor "Xondie" for product "Vodpod Video Gallery" and version "3.1.5" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | * | - |
Safe
|