{"api_version":"1","generated_at":"2026-07-23T12:03:29+00:00","cve":"CVE-2010-0452","urls":{"html":"https://cve.report/CVE-2010-0452","api":"https://cve.report/api/cve/CVE-2010-0452.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0452","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0452"},"summary":{"title":"CVE-2010-0452","description":"Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.","state":"PUBLISHED","assigner":"hp","published_at":"2010-03-29 18:30:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/38961","name":"http://www.securityfocus.com/bid/38961","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP Project and Portfolio Management Center Unspecified Cross Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/63175","name":"http://www.osvdb.org/63175","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=126953216625011&w=2","name":"http://marc.info/?l=bugtraq&m=126953216625011&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"'[security bulletin] HPSBMA02436 SSRT080064 rev.1 - HP Project and Portfolio Management Center (PPMC)' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1023749","name":"http://securitytracker.com/id?1023749","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - HP Project and Portfolio Management Center Input Validation Hole Permits Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39105","name":"http://secunia.com/advisories/39105","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"HP Project and Portfolio Management Center Cross-Site Scripting Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0452","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0452","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"452","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"hp","cpe5":"hp-ux","cpe6":"b.11.23","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"452","vulnerable":"1","versionEndIncluding":"7.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"project_and_portfolio_management_center","cpe6":"*","cpe7":"sp10","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"452","vulnerable":"1","versionEndIncluding":"7.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"project_and_portfolio_management_center","cpe6":"*","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:52:19.259Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"39105","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39105"},{"name":"HPSBMA02436","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=126953216625011&w=2"},{"name":"1023749","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1023749"},{"name":"38961","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/38961"},{"name":"SSRT080064","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=126953216625011&w=2"},{"name":"63175","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/63175"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-03-29T18:00:00.000Z","orgId":"74586083-13ce-40fd-b46a-8e5d23cfbcb2","shortName":"hp"},"references":[{"name":"39105","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39105"},{"name":"HPSBMA02436","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=126953216625011&w=2"},{"name":"1023749","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1023749"},{"name":"38961","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/38961"},{"name":"SSRT080064","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=126953216625011&w=2"},{"name":"63175","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/63175"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"hp-security-alert@hp.com","ID":"CVE-2010-0452","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"39105","refsource":"SECUNIA","url":"http://secunia.com/advisories/39105"},{"name":"HPSBMA02436","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=126953216625011&w=2"},{"name":"1023749","refsource":"SECTRACK","url":"http://securitytracker.com/id?1023749"},{"name":"38961","refsource":"BID","url":"http://www.securityfocus.com/bid/38961"},{"name":"SSRT080064","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=126953216625011&w=2"},{"name":"63175","refsource":"OSVDB","url":"http://www.osvdb.org/63175"}]}}}},"cveMetadata":{"assignerOrgId":"74586083-13ce-40fd-b46a-8e5d23cfbcb2","assignerShortName":"hp","cveId":"CVE-2010-0452","datePublished":"2010-03-29T18:00:00.000Z","dateReserved":"2010-01-27T00:00:00.000Z","dateUpdated":"2024-09-16T23:31:27.904Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-03-29 18:30:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:project_and_portfolio_management_center:*:sp10:*:*:*:*:*:*","versionEndIncluding":"7.1","matchCriteriaId":"73009E3C-9324-4CBD-9F00-536C866A6601"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:project_and_portfolio_management_center:*:sp3:*:*:*:*:*:*","versionEndIncluding":"7.5","matchCriteriaId":"34C16944-8E7C-4231-BAC4-2CDD4C963FF6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:hp:hp-ux:b.11.23:*:*:*:*:*:*:*","matchCriteriaId":"12C73959-3E02-4847-8962-651D652800EE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"452","Ordinal":"1","Title":"CVE-2010-0452","CVE":"CVE-2010-0452","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"452","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.","Type":"Description","Title":"CVE-2010-0452"},{"CveYear":"2010","CveId":"452","Ordinal":"2","NoteData":"2010-03-29","Type":"Other","Title":"Published"}]}}}