CVE-2010-4647: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4647?
CVE-2010-4647 is classified as a moderate severity vulnerability that allows for cross-site scripting attacks.
How do I fix CVE-2010-4647?
To fix CVE-2010-4647, update your Eclipse IDE to version 3.6.2 or later.
What systems are affected by CVE-2010-4647?
CVE-2010-4647 affects multiple versions of Eclipse IDE, including versions from 1.0 to 3.6.1.
What are the impacts of exploiting CVE-2010-4647?
Exploiting CVE-2010-4647 could allow attackers to inject arbitrary web scripts or HTML in the affected Eclipse Help Contents application.
Is CVE-2010-4647 still a concern today?
While CVE-2010-4647 is older, any unpatched systems still using vulnerable versions of Eclipse IDE remain at risk.