← All CVEs

CVE-2010-2103

medium · 4.3

Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.

4.3
CVSS
34.9%
EPSS (exploit prob.)
98th
EPSS percentile
2010-05-27
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
apacheaxis21.4.1
apacheaxis21.5.1
3comintelligent_management_centerall versions
sapbusiness_objects12
apacheaxis21.4.1
apacheaxis21.5.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-2103