CVE-2010-2103
Summary
| CVE | CVE-2010-2103 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-05-27 22:30:00 UTC |
| Updated | 2018-10-10 19:58:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | 3com | Intelligent Management Center | All | All | All | All |
| Application | 3com | Intelligent Management Center | All | All | All | All |
| Application | Apache | Axis2 | 1.4.1 | All | All | All |
| Application | Apache | Axis2 | 1.5.1 | All | All | All |
| Application | Apache | Axis2 | 1.4.1 | All | All | All |
| Application | Apache | Axis2 | 1.5.1 | All | All | All |
| Application | Sap | Business Objects | 12 | All | All | All |
| Application | Sap | Business Objects | 12 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Authenticated Cross-Site Scripting Vulnerability (XSS) within Apache Axis2 administration console | EXPLOIT-DB | www.exploit-db.com | Exploit |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| 64844 | OSVDB | osvdb.org | Exploit |
| spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObject... | MISC | spl0it.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Apache Axis2/Java "modules" Cross-Site Scripting Vulnerability - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| Apache Axis2 'engagingglobally' Cross-Site Scripting Vulnerability | BID | www.securityfocus.com | Exploit |
| ProCheckUp - Penetration Testing, PCI DSS Compliance, Application Testing | MISC | www.procheckup.com | Exploit |
| - Juniper Networks | CONFIRM | kb.juniper.net | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.