VulnerabilityModified
CVE-2007-3830
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.
LOW 3.5EPSS 2.16%
Does this matter?
Lower severity and a low EPSS score (2.16%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- ibm/proventia network ips gx5008 · ibm/proventia network ips gx5108
- Source
- cve@mitre.org
References
- http://osvdb.org/36475
- http://secunia.com/advisories/25979Vendor Advisory
- http://www.sybsecurity.com/hack-proventia-1.pdfExploit
- http://www.vupen.com/english/advisories/2007/2545
- http://osvdb.org/36475
- http://secunia.com/advisories/25979Vendor Advisory
- http://www.sybsecurity.com/hack-proventia-1.pdfExploit
- http://www.vupen.com/english/advisories/2007/2545
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.