Unrated severityNVD Advisory· Published Jan 3, 2011· Updated Apr 29, 2026
CVE-2010-4524
CVE-2010-4524
Description
Cross-site scripting (XSS) vulnerability in lib/mhtxthtml.pl in MHonArc 2.6.16 allows remote attackers to inject arbitrary web script or HTML via a malformed start tag and end tag for a SCRIPT element, as demonstrated by <scr<body>ipt> and </scr<body>ipt> sequences.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- openwall.com/lists/oss-security/2010/12/22/5nvdPatch
- openwall.com/lists/oss-security/2010/12/21/4nvdExploitPatch
- openwall.com/lists/oss-security/2010/12/22/4nvdExploitPatch
- bugzilla.redhat.com/show_bug.cginvdExploitPatch
- www.vupen.com/english/advisories/2010/3344nvdVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvd
- lists.mandriva.com/security-announce/2011-01/msg00004.phpnvd
- openwall.com/lists/oss-security/2010/12/21/7nvd
- savannah.nongnu.org/bugs/nvd
- secunia.com/advisories/42694nvd
- www.mail-archive.com/mhonarc-dev%40mhonarc.org/msg01296.htmlnvd
- www.securityfocus.com/bid/45528nvd
- www.vupen.com/english/advisories/2011/0067nvd
News mentions
0No linked articles in our index yet.