CVE-2010-1995
Tomatocms < 2.0.4 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with "Add new article" privileges, to inject arbitrary web script or HTML via the (1) title, (2) subTitle, and (3) author parameters in conjunction with a /admin/news/article/add PATH_INFO.
References (7)
Scores
EPSS
0.0034
EPSS Percentile
56.0%
Classification
CWE
CWE-79
Status
published
Affected Products (8)
tomatocms/tomatocms
< 2.0.4
tomatocms/tomatocms
tomatocms/tomatocms
tomatocms/tomatocms
tomatocms/tomatocms
tomatocms/tomatocms
tomatocms/tomatocms
n/a/n/a
Timeline
Published
May 20, 2010
Tracked Since
Feb 18, 2026