peter bassill · operator
$ cve CVE-2010-4749 JSON

CVE-2010-4749 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) body parameter to action.php and the (2) amount and (3) action parameters to admin/index.php.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS2.02% — more likely to be exploited than 80% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2011-03-01
Last modified2026-06-16

Affected (1)

VendorProduct
blogcmsblog\

Public exploits

SourceTitleDate
exploit-dbBlog:CMS 4.2.1e - Multiple Vulnerabilities2010-12-15

References

→ the Explorer  ·  watch your stack  ·  NVD