Candidate: CVE-2010-3070 PublicDate: 2010-09-28 18:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3070 Description: Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to an arbitrary PHP script that uses NuSOAP classes. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_nusoap: upstream_nusoap: released (0.7.3-4) dapper_nusoap: DNE hardy_nusoap: DNE jaunty_nusoap: DNE karmic_nusoap: ignored (reached end-of-life) lucid_nusoap: ignored (reached end-of-life) maverick_nusoap: ignored (reached end-of-life) natty_nusoap: not-affected (0.7.3-4) oneiric_nusoap: not-affected (0.7.3-4) precise_nusoap: not-affected (0.7.3-4) quantal_nusoap: not-affected (0.7.3-4) raring_nusoap: not-affected (0.7.3-4) saucy_nusoap: not-affected (0.7.3-4) devel_nusoap: not-affected (0.7.3-4)