CVE-2010-3931
Summary
| CVE | CVE-2010-3931 |
|---|---|
| State | PUBLISHED |
| Assigner | jpcert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-20 19:00:05 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rocomotion | Pm Bbs | All | All | All | All |
| Application | Rocomotion | Pm Forum | All | All | All | All |
| Application | Rocomotion | Pplog | All | All | All | All |
| Application | Rocomotion | Pplog 2 | All | All | All | All |
| Application | Rocomotion | P Board | All | All | All | All |
| Application | Rocomotion | P Diary R | All | All | All | All |
| Application | Rocomotion | P Forum | All | All | All | All |
| Application | Rocomotion | P Link | All | All | All | All |
| Application | Rocomotion | P Link Compact | All | All | All | All |
| Application | Rocomotion | P Up Board | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| JVN#09115481: Cross-site scripting vulnerability in multiple Rocomotion products | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | Third Party Advisory |
| Multiple Rocomotion products Unspecified Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Rocomotion Products Script Insertion Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000006.html | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | Third Party Advisory |
| osvdb.org/70495 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| P boardなど当サイトのPHPスクリプトをお使いの方へ | Another Rocomotion | af854a3a-2127-422b-91ae-364da2661108 | another.rocomotion.jp | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.