CVE-2010-4710
Publication date 28 January 2011
Last updated 24 July 2024
Ubuntu priority
Description
Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| yui | 11.10 oneiric | Ignored |
| 11.04 natty | Ignored | |
| 10.10 maverick | Ignored | |
| 10.04 LTS lucid | Ignored | |
| 9.10 karmic | Ignored end of life | |
| 8.04 LTS hardy | Ignored end of life | |
| 6.06 LTS dapper | Not in release |