CVE-2010-2316
Wmsdesign Wmscms < 2.0 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) sbr, (3) p, and (4) sbl parameters, different vectors than CVE-2007-3137.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Ariko-Security · textwebappsphp
https://www.exploit-db.com/exploits/13739
Scores
EPSS
0.0025
EPSS Percentile
47.9%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
wmsdesign/wmscms
< 2.0
n/a/n/a
Timeline
Published
Jun 17, 2010
Tracked Since
Feb 18, 2026