Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: jpcert
Published: 2011-01-20T18:00:00
Updated: 2024-08-07T03:26:12.154Z
Reserved: 2010-10-12T00:00:00
Link: CVE-2010-3931

No data.

Status : Deferred
Published: 2011-01-20T19:00:05.193
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-3931

No data.