Unrated severityNVD Advisory· Published Nov 2, 2011· Updated Apr 29, 2026
CVE-2010-5027
CVE-2010-5027
Description
Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: some of these details are obtained from third party information.
Affected products
2cpe:2.3:a:sfiab:science_fair_in_a_box:2.0.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sfiab:science_fair_in_a_box:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:sfiab:science_fair_in_a_box:2.2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- packetstormsecurity.org/1006-exploits/fairinabox-sqlxss.txtnvdExploit
- www.securityfocus.com/bid/40743nvdExploit
- secunia.com/advisories/40170nvdVendor Advisory
- securityreason.com/securityalert/8516nvd
- www.exploit-db.com/exploits/13801nvd
- www.osvdb.org/65419nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/59283nvd
News mentions
0No linked articles in our index yet.