Unrated severityNVD Advisory· Published Jun 15, 2010· Updated Jun 16, 2026
CVE-2010-2265
CVE-2010-2265
Description
Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
- Range: Windows XP, Windows Server 2003
Patches
Vulnerability mechanics
References
10- archives.neohapsis.com/archives/fulldisclosure/2010-06/0197.htmlnvdExploit
- www.securityfocus.com/bid/40721nvdExploit
- blogs.technet.com/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspxnvdVendor Advisory
- blogs.technet.com/b/srd/archive/2010/06/10/help-and-support-center-vulnerability-full-disclosure-posting.aspxnvdVendor Advisory
- secunia.com/advisories/40076nvdVendor Advisory
- www.microsoft.com/technet/security/advisory/2219475.mspxnvdVendor Advisory
- www.vupen.com/english/advisories/2010/1417nvdVendor Advisory
- www.kb.cert.org/vuls/id/578319nvdUS Government Resource
- www.securityfocus.com/archive/1/511774/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/59267nvd
News mentions
0No linked articles in our index yet.