VulnerabilityModified
CVE-2007-1181
WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors.
MEDIUM 5.0EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- web-app.org/webapp
- Source
- cve@mitre.org
References
- http://osvdb.org/33291
- http://secunia.com/advisories/24080Vendor Advisory
- http://www.securityfocus.com/bid/22563Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/0604
- http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250
- http://osvdb.org/33291
- http://secunia.com/advisories/24080Vendor Advisory
- http://www.securityfocus.com/bid/22563Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/0604
- http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.