CVE-2010-2103

Apache Axis2 1.4.1-1.5.1 - Cross-Site Scripting via Modules Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-2103. PoCs published by Richard Brain.

AI-analyzed exploit summary This exploit demonstrates an authenticated Cross-Site Scripting (XSS) vulnerability in Apache Axis2 administration console. The PoC shows how an attacker can inject a malicious script into the 'modules' parameter, which executes in the context of the user's session.

Description

Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC
by Richard Brain · textwebappsmultiple
https://www.exploit-db.com/exploits/12689

This exploit demonstrates an authenticated Cross-Site Scripting (XSS) vulnerability in Apache Axis2 administration console. The PoC shows how an attacker can inject a malicious script into the 'modules' parameter, which executes in the context of the user's session.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Apache Axis2 1.4.1
Auth required
Prerequisites: Authenticated access to the Axis2 administration console
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/58790
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39906
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/12689
Vendor Advisory x_refsource_confirm
https://kb.juniper.net/KB27373
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1215
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/40327
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/511404/100/0/threaded
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/64844

Scores

EPSS 0.3493
EPSS Percentile 98.2%

Details

CWE
CWE-79
Status published
Products (3)
apache/axis2 1.4.1
apache/axis2 1.5.1
org.apache.axis2.wso2/axis2 1.4.1 - 1.6.0Maven
Published May 27, 2010
Tracked Since Feb 18, 2026