Vulnerability Details CVE-2010-2477
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.9%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2010-2477
-
cpe:2.3:a:pythonpaste:paste:*
-
cpe:2.3:a:pythonpaste:paste:0.1.0
-
cpe:2.3:a:pythonpaste:paste:0.3
-
cpe:2.3:a:pythonpaste:paste:0.4.1
-
cpe:2.3:a:pythonpaste:paste:0.5
-
cpe:2.3:a:pythonpaste:paste:0.9.1
-
cpe:2.3:a:pythonpaste:paste:0.9.2
-
cpe:2.3:a:pythonpaste:paste:0.9.3
-
cpe:2.3:a:pythonpaste:paste:0.9.4
-
cpe:2.3:a:pythonpaste:paste:1.0.1
-
cpe:2.3:a:pythonpaste:paste:1.1
-
cpe:2.3:a:pythonpaste:paste:1.1.1
-
cpe:2.3:a:pythonpaste:paste:1.2
-
cpe:2.3:a:pythonpaste:paste:1.3
-
cpe:2.3:a:pythonpaste:paste:1.4
-
cpe:2.3:a:pythonpaste:paste:1.4.2
-
cpe:2.3:a:pythonpaste:paste:1.5
-
cpe:2.3:a:pythonpaste:paste:1.6
-
cpe:2.3:a:pythonpaste:paste:1.7
-
cpe:2.3:a:pythonpaste:paste:1.7.1
-
cpe:2.3:a:pythonpaste:paste:1.7.2
-
cpe:2.3:a:pythonpaste:paste:1.7.3