CVE-2007-0583
Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander 6.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) LogoffMessage parameter to logofflast.aspx or the (2) txtUsername parameter to…
Does this matter?
Lower severity and a low EPSS score (1.73%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander 6.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) LogoffMessage parameter to logofflast.aspx or the (2) txtUsername parameter to Default.aspx. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.73% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- http commander/http commander
- Source
- cve@mitre.org
References
- http://osvdb.org/32985
- http://osvdb.org/32986
- http://secunia.com/advisories/23964Vendor Advisory
- http://www.securityfocus.com/bid/22298
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31877
- http://osvdb.org/32985
- http://osvdb.org/32986
- http://secunia.com/advisories/23964Vendor Advisory
- http://www.securityfocus.com/bid/22298
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31877
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.