← Vulnerability feed

Vulnerability record · CVE-2010-2734 · published 10 November 2010

CVE-2010-2734: Microsoft forefront unified access gateway cross-site scripting vulnerability

Microsoft · Forefront Unified Access Gateway

Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."

4.3 CVSS 2.0 Medium EPSS 14% · top 3.5% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-2734 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12571Microsoft forefront unified access gateway server-side request forgery (ssrf) vulnerabilityuniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries fo…EPSS 30%9.3CVE-2011-1969Microsoft forefront unified access gateway code injection vulnerabilityMicrosoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Jav…EPSS 17%5.8CVE-2012-0146Microsoft forefront unified access gateway improper input validation vulnerabilityOpen redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users t…EPSS 11%5.8CVE-2010-2732Microsoft forefront unified access gateway improper input validation vulnerabilityOpen redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allo…EPSS 13%5.0CVE-2012-0147Microsoft forefront unified access gateway vulnerabilityMicrosoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote atta…EPSS 36%5.0CVE-2011-2012Microsoft forefront unified access gateway improper input validation vulnerabilityMicrosoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remo…EPSS 17%4.3CVE-2011-1895Microsoft forefront unified access gateway code injection vulnerabilityCRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to in…EPSS 11%4.3CVE-2011-1896Microsoft forefront unified access gateway cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote att…EPSS 8.3%

Source: NIST National Vulnerability Database (record CVE-2010-2734), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.