CVE-2010-2103
Apache Axis2 < 1.6.0 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
exploitdb
WORKING POC
by Richard Brain · textwebappsmultiple
https://www.exploit-db.com/exploits/12689
References (10)
Scores
EPSS
0.2177
EPSS Percentile
95.7%
Classification
CWE
CWE-79
Status
published
Affected Products (4)
apache/axis2
apache/axis2
org.apache.axis2.wso2/axis2
< 1.6.0Maven
n/a/n/a
Timeline
Published
May 27, 2010
Tracked Since
Feb 18, 2026