CVE-2010-1905

Consona Live Assistance - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HTML via crafted input to ASP pages, as demonstrated using the backurl parameter to sdccommon/verify/asp/n6plugindestructor.asp.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ruben Santamarta · textwebappsasp
https://www.exploit-db.com/exploits/33959

Scores

EPSS 0.0329
EPSS Percentile 87.0%

Classification

CWE
CWE-79
Status published

Affected Products (6)

consona/consona_live_assistance
consona/consona_dynamic_agent
consona/consona_dynamic_agent
consona/consona_dynamic_agent
consona/consona_subscriber_assistance
n/a/n/a

Timeline

Published May 12, 2010
Tracked Since Feb 18, 2026