CVE-2007-3991
Multiple cross-site scripting (XSS) vulnerabilities in cv.asp in Asp cvmatik 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz (Ady), (2) Soyadiniz (Soyady), (3) Ehliyet, (4) Askerlik, and (5) GSM…
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in cv.asp in Asp cvmatik 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz (Ady), (2) Soyadiniz (Soyady), (3) Ehliyet, (4) Askerlik, and (5) GSM parameters; and possibly other unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- asp indir/cvmatik
- Source
- cve@mitre.org
References
- http://downloads.securityfocus.com/vulnerabilities/exploits/25008.htmlExploit
- http://osvdb.org/36471
- http://secunia.com/advisories/26174Vendor Advisory
- http://www.securityfocus.com/bid/25008Exploit
- http://www.vupen.com/english/advisories/2007/2604
- http://downloads.securityfocus.com/vulnerabilities/exploits/25008.htmlExploit
- http://osvdb.org/36471
- http://secunia.com/advisories/26174Vendor Advisory
- http://www.securityfocus.com/bid/25008Exploit
- http://www.vupen.com/english/advisories/2007/2604
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.