Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2010-2692

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

2daybiz Custom T-Shirt Design Script存在跨站脚本攻击漏洞。远程攻击者可以借助review命令注入任意的web脚本或HTML。

AI Predicted 6.1 Difficulty: Easy EPSS 1.71% · P75
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2010-2692

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Cross-site scripting (XSS) vulnerability in 2daybiz Custom T-Shirt Design Script allows remote attackers to inject arbitrary web script or HTML via a review comment.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
2daybiz Custom T-Shirt Design Script跨站脚本攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
2daybiz Custom T-Shirt Design Script存在跨站脚本攻击漏洞。远程攻击者可以借助review命令注入任意的web脚本或HTML。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2010-2692

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-2692

登录查看更多情报信息。

Vendor Advisories for CVE-2010-2692 (3)

Exploits & Public PoCs for CVE-2010-2692 (1)

Same Patch Batch · n/a · 2010-07-09 · 25 CVEs total

CVE-2010-2691 2daybiz Custom T-Shirt Design Script 多个SQL注入漏洞
CVE-2009-4935 Esoftpro Online Guestbook Pro 'ogp_show.php'SQL注入漏洞
CVE-2009-4934 Esoftpro Online Photo Pro 'section' 参数跨站脚本攻击漏洞
CVE-2009-4933 Winterwebs EZ Webitor 'login.php'多个SQL注入漏洞
CVE-2009-4932 Mpesch3.De1 1by1 .m3u文件处理栈溢出漏洞
CVE-2009-4931 Bestwebsharing Groovy Media Player '.m3u' File 远程栈缓冲区溢出漏洞
CVE-2009-4930 SunGard Banner Student 'twbkwbis.P_SecurityQuestion'跨站脚本攻击漏洞
CVE-2009-4929 Sweetphp TotalCalendar 'manage_users.php'远程密码修改漏洞
CVE-2009-4928 Sweetphp TotalCalendar 'config.php' 多个PHP远程文件包含漏洞
CVE-2009-4927 Webmobo WB News 不安全Cookie认证绕过漏洞
CVE-2009-4926 Esoftpro Online Contact Manager多个跨站脚本攻击漏洞
CVE-2009-4925 Creasito多个SQL注入漏洞
CVE-2010-2489 Ruby-Lang ARGF.inplace_mode变量缓冲区溢出漏洞
CVE-2010-2690 JOOFORGE Gamesbox SQL注入漏洞
CVE-2010-2689 Internet DM WebDM CMS 'cont_form.php'SQL注入漏洞
CVE-2010-2688 Site2Nite Boat Classifieds 'detail.asp' SQL注入漏洞
CVE-2010-2687 Site2Nite Boat Classifieds 'printdetail.asp' SQL注入漏洞
CVE-2010-2686 TopManage OLK 'clientes.asp'多个SQL注入漏洞
CVE-2010-2685 Customer Paradigm PageDirector CMS 'siteadmin/adduser.php'安全限制绕过漏洞
CVE-2010-2684 Customer Paradigm PageDirector 'id'参数SQL注入漏洞

Showing top 20 of 25 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-2692

No comments yet


Leave a comment