CVE-2011-0772
Pivotx - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitrary web script or HTML via the (1) color parameter to includes/blogroll.php or (2) src parameter to includes/timwrapper.php.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/35259
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/35260
References (13)
Scores
EPSS
0.1018
EPSS Percentile
93.0%
Classification
CWE
CWE-79
Status
published
Affected Products (9)
pivotx/pivotx
pivotx/pivotx
pivotx/pivotx
pivotx/pivotx
pivotx/pivotx
pivotx/pivotx
pivotx/pivotx
pivotx/pivotx
n/a/n/a
Timeline
Published
Feb 04, 2011
Tracked Since
Feb 18, 2026