CVE-2010-4710

Publication date 28 January 2011

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570.

Read the notes from the security team

Status

Package Ubuntu Release Status
yui 11.10 oneiric Ignored
11.04 natty Ignored
10.10 maverick Ignored
10.04 LTS lucid Ignored
9.10 karmic Ignored end of life
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Not in release

Notes


jdstrand

documentation issue