Record summary

CVE-2010-5284 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to manageuser.php, (2) y parameter in a newcal action to manageajax.php, and the (3) pic parameter to thumb.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBCollabtive 0.65 - Multiple VulnerabilitiesExploitDB exploitby Anatolia SecurityNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

6