CVE-2010-4749

BLOG:CMS 4.2.1.e - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) body parameter to action.php and the (2) amount and (3) action parameters to admin/index.php.

Exploits (1)

exploitdb WORKING POC
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/15743

Scores

EPSS 0.0693
EPSS Percentile 91.3%

Classification

CWE
CWE-79
Status published

Affected Products (2)

blogcms/blog\
n/a/n/a

Timeline

Published Mar 01, 2011
Tracked Since Feb 18, 2026