VulnerabilityModified
CVE-2007-0399
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action.
MEDIUM 6.0EPSS 2.12%
Does this matter?
Lower severity and a low EPSS score (2.12%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 2.12% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- simple machines/simple machines forum
- Source
- cve@mitre.org
References
- http://aria-security.com/forum/showthread.php?p=128
- http://osvdb.org/32606
- http://securityreason.com/securityalert/2169
- http://www.securityfocus.com/archive/1/457508/100/0/threaded
- http://www.securityfocus.com/archive/1/457627/100/0/threaded
- http://www.securityfocus.com/archive/1/457761/100/200/threaded
- http://www.securityfocus.com/archive/1/458194/100/100/threaded
- http://www.securityfocus.com/archive/1/458904/100/0/threaded
- http://www.securityfocus.com/bid/22143
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31612
- http://aria-security.com/forum/showthread.php?p=128
- http://osvdb.org/32606
- http://securityreason.com/securityalert/2169
- http://www.securityfocus.com/archive/1/457508/100/0/threaded
- http://www.securityfocus.com/archive/1/457627/100/0/threaded
- http://www.securityfocus.com/archive/1/457761/100/200/threaded
- http://www.securityfocus.com/archive/1/458194/100/100/threaded
- http://www.securityfocus.com/archive/1/458904/100/0/threaded
- http://www.securityfocus.com/bid/22143
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31612
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.