CVE-2010-1104
Zope <2.8.12-2.12.3 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.
References (6)
Scores
EPSS
0.0044
EPSS Percentile
63.0%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
zope/zope
... and 35 more
Timeline
Published
Mar 25, 2010
Tracked Since
Feb 18, 2026