CVE-2010-2477

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/11/2010
Last modified:
11/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pythonpaste:paste:*:*:*:*:*:*:*:* 1.7.3.1 (including)
cpe:2.3:a:pythonpaste:paste:0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:0.3:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:0.4.1:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:0.5:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:0.9.4:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:1.1:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:1.2:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:1.3:*:*:*:*:*:*:*
cpe:2.3:a:pythonpaste:paste:1.4:*:*:*:*:*:*:*