Unrated severityNVD Advisory· Published Feb 4, 2011· Updated Apr 29, 2026
CVE-2011-0772
CVE-2011-0772
Description
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitrary web script or HTML via the (1) color parameter to includes/blogroll.php or (2) src parameter to includes/timwrapper.php.
Affected products
8cpe:2.3:a:pivotx:pivotx:2.1.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:pivotx:pivotx:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:pivotx:pivotx:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:pivotx:pivotx:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:pivotx:pivotx:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:pivotx:pivotx:2.2.0:b1:*:*:*:*:*:*
- cpe:2.3:a:pivotx:pivotx:2.2.0:b2:*:*:*:*:*:*
- cpe:2.3:a:pivotx:pivotx:2.2.0:rc:*:*:*:*:*:*
- cpe:2.3:a:pivotx:pivotx:2.2.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- blog.pivotx.net/archive/2011/01/11/pivotx-222-releasednvdPatchVendor Advisory
- www.htbridge.ch/advisory/xss_in_pivotx.htmlnvdExploit
- www.htbridge.ch/advisory/xss_in_pivotx_1.htmlnvdExploit
- www.osvdb.org/70673nvdExploit
- www.osvdb.org/70674nvdExploit
- www.securityfocus.com/bid/45996nvdExploit
- secunia.com/advisories/43040nvdVendor Advisory
- pivot-weblog.svn.sf.net/viewvc/pivot-weblognvd
- pivot-weblog.svn.sf.net/viewvc/pivot-weblognvd
- securityreason.com/securityalert/8062nvd
- www.securityfocus.com/archive/1/515958/100/0/threadednvd
- www.securityfocus.com/archive/1/515964/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/64975nvd
News mentions
0No linked articles in our index yet.