← Vulnerability feed

Vulnerability record · CVE-2010-3906 · published 17 December 2010

CVE-2010-3906: Git cross-site scripting vulnerability

Git · Git

Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.

4.3 CVSS 2.0 Medium EPSS 5.6% · top 7.3% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
5.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
30References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052518.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052782.html
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00004.html
http://secunia.com/advisories/42645 Vendor Advisory
http://secunia.com/advisories/42731
http://secunia.com/advisories/42743
http://secunia.com/advisories/43457
http://www.exploit-db.com/exploits/15744 Exploit
http://www.mandriva.com/security/advisories?name=MDVSA-2010:256
http://www.redhat.com/support/errata/RHSA-2010-1003.html
http://www.securityfocus.com/bid/45439 Exploit
http://www.securitytracker.com/id?1024905
http://www.vupen.com/english/advisories/2010/3323
http://www.vupen.com/english/advisories/2011/0010
http://www.vupen.com/english/advisories/2011/0464
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052518.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052782.html
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00004.html
http://secunia.com/advisories/42645 Vendor Advisory
http://secunia.com/advisories/42731
http://secunia.com/advisories/42743
http://secunia.com/advisories/43457
http://www.exploit-db.com/exploits/15744 Exploit
http://www.mandriva.com/security/advisories?name=MDVSA-2010:256
http://www.redhat.com/support/errata/RHSA-2010-1003.html
http://www.securityfocus.com/bid/45439 Exploit
http://www.securitytracker.com/id?1024905
http://www.vupen.com/english/advisories/2010/3323
http://www.vupen.com/english/advisories/2011/0010
http://www.vupen.com/english/advisories/2011/0464

Track CVE-2010-3906 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.0CVE-2025-48384Git config CRLF handling allows submodule path link-following code executionGit mishandles trailing carriage returns when writing config values, so a submodule path ending in CR is read back altered during submodule initializ…KEVEPSS 4.1%analysed9.8CVE-2022-23521Git gitattributes parsing integer overflow enables heap corruptionGit's gitattributes parser suffers multiple integer overflows when handling a huge number of path patterns, many attributes for one pattern, or very …EPSS 56%analysed9.8CVE-2022-41903Git-scm git integer overflow vulnerabilityGit is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality …EPSS 44%9.8CVE-2022-25648Git argument injection vulnerabilityThe package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) fu…EPSS 4.9%9.8CVE-2014-9390Git clients execute commands via crafted .git/config on case-insensitive filesystemsGit, Mercurial, libgit2, JGit, EGit and Xcode mishandle crafted .git/config paths on Windows and OS X, allowing a remote repository to place a file t…EPSS 76%analysed9.8CVE-2019-1353Git-scm git vulnerabilityAn issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running …EPSS 2.2%9.8CVE-2018-19486Git-scm git untrusted search path vulnerabilityGit before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involv…EPSS 4.1%9.8CVE-2018-17456Git recursive clone argument injection enables remote code executionGit versions before the fixed releases mishandle a .gitmodules URL field that begins with a '-' character during recursive 'git clone' of a superproj…EPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2010-3906), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.