← Voltar para CVEs
CVE-2007-4711
N/ADescricao
Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage, (2) mail, and (3) name parameters in a show action to (a) form.php; the (4) language and (5) anzeigebreite parameters to (b) admin/header.php; and the (6) msg parameter to (c) install.php, different vectors than CVE-2006-0706.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado9/5/2007
Ultima modificacao4/23/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
www.toms-seiten.at:toms_gaestebuch
Fraquezas (CWE)
CWE-79
Referencias
http://secunia.com/advisories/26662(cve@mitre.org)
http://securityreason.com/securityalert/3097(cve@mitre.org)
http://www.osvdb.org/36735(cve@mitre.org)
http://www.osvdb.org/36736(cve@mitre.org)
http://www.securityfocus.com/archive/1/478360/100/0/threaded(cve@mitre.org)
http://www.securityfocus.com/archive/1/478803/100/0/threaded(cve@mitre.org)
http://www.securityfocus.com/bid/25507(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/36404(cve@mitre.org)
http://secunia.com/advisories/26662(af854a3a-2127-422b-91ae-364da2661108)
http://securityreason.com/securityalert/3097(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/36735(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/36736(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/archive/1/478360/100/0/threaded(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/archive/1/478803/100/0/threaded(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/25507(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/36404(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.