Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
Software | From | Fixed in |
---|---|---|
microsoft / windows_xp | - | - |
microsoft / windows_xp | --sp2 | --sp2.x |
microsoft / windows_server_2003 | - | - |
microsoft / windows_2003_server | - | - |