CVE-2010-4932
Entrans < 0.3.3 - Cross-Site Scripting via Search Query Parameter
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in search.php in Entrans before 0.3.3 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://www.htbridge.ch/advisory/xss_vulnerability_in_entrans.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/41543
Scores
EPSS
0.0087
EPSS Percentile
55.1%
Details
CWE
CWE-79
Status
published
Products (5)
khader_abbeb/entrans
0.1.1
khader_abbeb/entrans
0.2
khader_abbeb/entrans
0.3
khader_abbeb/entrans
0.3.1
khader_abbeb/entrans
< 0.3.2
Published
Oct 09, 2011
Tracked Since
Feb 18, 2026