{ "schema_version": "1.4.0", "id": "GHSA-v7q8-wvvh-c97p", "modified": "2020-06-16T21:57:13Z", "published": "2018-07-23T19:51:28Z", "aliases": [ "CVE-2010-1104" ], "summary": "Moderate severity vulnerability that affects Zope2", "details": "Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.", "severity": [], "affected": [ { "package": { "ecosystem": "PyPI", "name": "Zope2" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "2.8.0" }, { "fixed": "2.8.12" } ] } ] }, { "package": { "ecosystem": "PyPI", "name": "Zope2" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "2.9.0" }, { "fixed": "2.9.12" } ] } ] }, { "package": { "ecosystem": "PyPI", "name": "Zope2" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "2.10.0" }, { "fixed": "2.10.11" } ] } ] }, { "package": { "ecosystem": "PyPI", "name": "Zope2" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "2.11.0" }, { "fixed": "2.11.6" } ] } ] }, { "package": { "ecosystem": "PyPI", "name": "Zope2" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "2.12.0" }, { "fixed": "2.12.3" } ] } ] } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-1104" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/55599" }, { "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-v7q8-wvvh-c97p" }, { "type": "WEB", "url": "https://mail.zope.org/pipermail/zope-announce/2010-January/002229.html" }, { "type": "WEB", "url": "http://secunia.com/advisories/38007" }, { "type": "WEB", "url": "http://www.osvdb.org/61655" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/37765" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2010/0104" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:57:13Z", "nvd_published_at": null } }