{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T16:28:48.522","vulnerabilities":[{"cve":{"id":"CVE-2010-3314","sourceIdentifier":"secalert@redhat.com","published":"2010-09-22T19:00:03.837","lastModified":"2026-06-16T23:22:34.063","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script or HTML via the lang parameter."},{"lang":"es","value":"Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en EGroupware v1.4.001+.002; v1.6.001+.002 y posiblemente otras versioens anteriores a v1.6.003; y EPL v9.1 anterior a v9.1.20100309 y v9.2 anterior a v9.2.20100309; \r\npermite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro lang"}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:egroupware:egroupware:1.4.001:*:*:*:*:*:*:*","matchCriteriaId":"F22F0392-6D7A-4133-83AA-C14F1B69A167"},{"vulnerable":true,"criteria":"cpe:2.3:a:egroupware:egroupware:1.4.001\\+.002:*:*:*:*:*:*:*","matchCriteriaId":"65987EB6-F4D8-47C9-B95F-DEA15E94A3AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:egroupware:egroupware:1.4.002:*:*:*:*:*:*:*","matchCriteriaId":"896271FE-50B1-436B-8926-1CE685667D03"},{"vulnerable":true,"criteria":"cpe:2.3:a:egroupware:egroupware:1.6.001:*:*:*:*:*:*:*","matchCriteriaId":"7AE768DF-9605-40FA-8840-C60D2C0DCE0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:egroupware:egroupware:1.6.001\\+.002:*:*:*:*:*:*:*","matchCriteriaId":"C105EFE2-0592-45B3-A362-4208245EDD9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:egroupware:egroupware:1.6.002:*:*:*:*:*:*:*","matchCriteriaId":"FDB7B153-61AE-499D-8577-CC83CC100C43"},{"vulnerable":true,"criteria":"cpe:2.3:a:egroupware:egroupware:9.1:-:commercial_epl:*:*:*:*:*","matchCriteriaId":"C9D0492E-A33E-43D4-8E57-C74D677A1B99"},{"vulnerable":true,"criteria":"cpe:2.3:a:egroupware:egroupware:9.2:-:commercial_epl:*:*:*:*:*","matchCriteriaId":"37AD8770-074D-42E3-81CC-E3A7D8856FD2"}]}]}],"references":[{"url":"http://www.debian.org/security/2010/dsa-2013","source":"secalert@redhat.com"},{"url":"http://www.egroupware.org/news?item=93","source":"secalert@redhat.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.exploit-db.com/exploits/11777/","source":"secalert@redhat.com","tags":["Exploit"]},{"url":"http://www.openwall.com/lists/oss-security/2010/09/21/7","source":"secalert@redhat.com"},{"url":"http://www.debian.org/security/2010/dsa-2013","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.egroupware.org/news?item=93","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://www.exploit-db.com/exploits/11777/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"http://www.openwall.com/lists/oss-security/2010/09/21/7","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}