CVE-2010-2267
Accoria Rock Web Server - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Accoria Web Server (aka Rock Web Server) 1.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the getenv sample program, (2) the desc parameter to loadstatic.cgi, (3) the name parameter to httpdcfg.cgi, or (4) the dns parameter to servercfg.cgi.
Scores
EPSS
0.0029
EPSS Percentile
52.5%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
accoria/rock_web_server
n/a/n/a
Timeline
Published
Jun 15, 2010
Tracked Since
Feb 18, 2026