CVE-2010-2103

Apache Axis2 < 1.6.0 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC
by Richard Brain · textwebappsmultiple
https://www.exploit-db.com/exploits/12689

Scores

EPSS 0.2177
EPSS Percentile 95.7%

Classification

CWE
CWE-79
Status published

Affected Products (4)

apache/axis2
apache/axis2
org.apache.axis2.wso2/axis2 < 1.6.0Maven
n/a/n/a

Timeline

Published May 27, 2010
Tracked Since Feb 18, 2026