CVE-2010-3906
Git < 1.7.3.3 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.
Exploits (1)
References (15)
Scores
EPSS
0.1392
EPSS Percentile
94.2%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
git/git
git/git
git/git
git/git
git/git
git/git
git/git
git/git
git/git
git/git
git/git
git/git
git/git
git/git
git/git
... and 35 more
Timeline
Published
Dec 17, 2010
Tracked Since
Feb 18, 2026