This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Deliciousdays First view 2010-11-03
Product Cforms Last view 2010-11-03
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:deliciousdays:cforms:11.5:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
4.3 2010-11-03 CVE-2010-3977

Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Open Source Vulnerability Database (OSVDB)

id Description
69339 cforms Plugin for WordPress wp-content/plugins/cforms/lib_ajax.php Multiple P...

OpenVAS Exploits

id Description
2010-11-16 Name : WordPress Plugin cformsII 'lib_ajax.php' Multiple HTML Injection Vulnerabilities
File : nvt/gb_wordpress_mult_html_injection_vuln.nasl

Nessus® Vulnerability Scanner

id Description
2010-11-08 Name: The remote web server hosts a PHP script that is vulnerable to a cross-site s...
File: cforms_rs_xss.nasl - Type: ACT_ATTACK