Unrated severityNVD Advisory· Published Nov 23, 2011· Updated Apr 29, 2026
CVE-2010-5048
CVE-2010-5048
Description
Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php.
Affected products
1- cpe:2.3:a:joomlatune:com_jcomments:2.1.0.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.htbridge.ch/advisory/xss_vulnerability_in_jcomments_joomla.htmlnvdExploit
- www.securityfocus.com/bid/40230nvdExploitPatch
- secunia.com/advisories/39842nvdVendor Advisory
- packetstormsecurity.org/1005-exploits/joomlajcomments-xss.txtnvd
- www.joomlatune.com/jcomments-v.2.2-release-notes.htmlnvd
- www.securityfocus.com/archive/1/511320/100/0/threadednvd
News mentions
0No linked articles in our index yet.