CVE-2010-3906
EPSS 13.9%
Description
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.
How to fix CVE-2010-3906
To remediate CVE-2010-3906, upgrade the affected package to a fixed version below.
- Debian/git—upgrade to 1:1.7.2.3-2.2 or later
Is CVE-2010-3906 being exploited?
Moderate — EPSS is 13.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1:1.7.2.3-2.2