Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-07T03:26:12.154Z
Reserved: 2010-10-12T00:00:00
Link: CVE-2010-3931

No data.

Status : Deferred
Published: 2011-01-20T19:00:05.193
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-3931

No data.

No data.