{"api_version":"1","generated_at":"2026-07-23T08:14:31+00:00","cve":"CVE-2010-2256","urls":{"html":"https://cve.report/CVE-2010-2256","api":"https://cve.report/api/cve/CVE-2010-2256.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2256","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2256"},"summary":{"title":"CVE-2010-2256","description":"Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-06-09 20:30:24","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://packetstormsecurity.org/1001-exploits/ppmvcs-sqlxss.txt","name":"http://packetstormsecurity.org/1001-exploits/ppmvcs-sqlxss.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Files ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38086","name":"http://secunia.com/advisories/38086","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA38086 - Pay Per Minute Video Chat Script Cross-Site Scripting Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/10983","name":"http://www.exploit-db.com/exploits/10983","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Pay Per Minute Video Chat Script v2.0 and 2.1 Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2256","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2256","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2256","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"payperviewvideosoftware","cpe5":"pay_per_minute_video_chat_script","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2256","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"payperviewvideosoftware","cpe5":"pay_per_minute_video_chat_script","cpe6":"2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:25:07.637Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"38086","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38086"},{"name":"10983","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/10983"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.org/1001-exploits/ppmvcs-sqlxss.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-01-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-02-27T17:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"38086","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38086"},{"name":"10983","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/10983"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.org/1001-exploits/ppmvcs-sqlxss.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-2256","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"38086","refsource":"SECUNIA","url":"http://secunia.com/advisories/38086"},{"name":"10983","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/10983"},{"name":"http://packetstormsecurity.org/1001-exploits/ppmvcs-sqlxss.txt","refsource":"MISC","url":"http://packetstormsecurity.org/1001-exploits/ppmvcs-sqlxss.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-2256","datePublished":"2010-06-09T20:00:00.000Z","dateReserved":"2010-06-09T00:00:00.000Z","dateUpdated":"2024-08-07T02:25:07.637Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-06-09 20:30:24","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:payperviewvideosoftware:pay_per_minute_video_chat_script:2.0:*:*:*:*:*:*:*","matchCriteriaId":"A002D4AF-705B-4BA8-B04F-83388F66C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:payperviewvideosoftware:pay_per_minute_video_chat_script:2.1:*:*:*:*:*:*:*","matchCriteriaId":"EFCD0BD3-2712-4927-B666-6A99D224E636"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2256","Ordinal":"1","Title":"CVE-2010-2256","CVE":"CVE-2010-2256","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2256","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php.","Type":"Description","Title":"CVE-2010-2256"},{"CveYear":"2010","CveId":"2256","Ordinal":"2","NoteData":"2010-06-09","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"2256","Ordinal":"3","NoteData":"2017-02-27","Type":"Other","Title":"Modified"}]}}}