VulnerabilityModified
CVE-2007-3137
Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter.
MEDIUM 4.3EPSS 1.80%
Does this matter?
Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- webmaster solutions/wmscms
- Source
- cve@mitre.org
References
- http://osvdb.org/37144
- http://secunia.com/advisories/25583Vendor Advisory
- http://securityreason.com/securityalert/2789
- http://www.securityfocus.com/archive/1/470758/100/0/threaded
- http://www.securityfocus.com/bid/24365Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34763
- http://osvdb.org/37144
- http://secunia.com/advisories/25583Vendor Advisory
- http://securityreason.com/securityalert/2789
- http://www.securityfocus.com/archive/1/470758/100/0/threaded
- http://www.securityfocus.com/bid/24365Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34763
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.