CVE-2010-4647

Eclipse Ide < 3.6.1 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Aung Khant · textremotelinux
https://www.exploit-db.com/exploits/34999
exploitdb WORKING POC VERIFIED
by Aung Khant · textremotelinux
https://www.exploit-db.com/exploits/34998

Scores

EPSS 0.0964
EPSS Percentile 92.8%

Classification

CWE
CWE-79
Status published

Affected Products (40)

eclipse/eclipse_ide < 3.6.1
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
eclipse/eclipse_ide
... and 25 more

Timeline

Published Jan 13, 2011
Tracked Since Feb 18, 2026