CVE-2010-0726

Publication date 2 March 2010

Last updated 24 July 2024


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in the tb-send.rb (TrackBack transmission) plugin in tDiary 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors, possibly related to the (1) plugin_tb_url and (2) plugin_tb_excerpt parameters.

Status

Package Ubuntu Release Status
tdiary 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Fixed 2.2.1-1+lenny1build0.9.10.1
9.04 jaunty
Fixed 2.2.1-1+lenny1build0.9.04.1
8.10 intrepid
Fixed 2.2.1-1+lenny1build0.8.10.1
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Ignored end of life