CVE-2010-5064
Virtual War 1.6.1 R2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web script or HTML via (1) the Additional Information field to challenge.php, the (2) Additional Information or (3) Contact information field to joinus.php, (4) the War Report field to admin/admin.php in a finishwar action, or (5) the Nick field to profile.php.
Scores
EPSS
0.0022
EPSS Percentile
45.0%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
vwar/virtual_war
n/a/n/a
Timeline
Published
Oct 08, 2012
Tracked Since
Feb 18, 2026