CVE-2007-4265
Multiple cross-site scripting (XSS) vulnerabilities in VisionProject 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) projectIssueId parameter in EditProjectIssue.do, the (2) projectId parameter in…
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in VisionProject 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) projectIssueId parameter in EditProjectIssue.do, the (2) projectId parameter in ProjectSelected.do, the (3) folderId parameter in ProjectDocuments.do and the (4) sortField parameter in ProjectIssues.do.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- visionera ab/visionproject
- Source
- cve@mitre.org
References
- http://osvdb.org/36433
- http://osvdb.org/36434
- http://osvdb.org/36435
- http://osvdb.org/36436
- http://pridels-team.blogspot.com/2007/08/visionproject-multiple-xss-vuln.html
- http://secunia.com/advisories/26346Vendor Advisory
- http://www.securityfocus.com/bid/25218Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35825
- http://osvdb.org/36433
- http://osvdb.org/36434
- http://osvdb.org/36435
- http://osvdb.org/36436
- http://pridels-team.blogspot.com/2007/08/visionproject-multiple-xss-vuln.html
- http://secunia.com/advisories/26346Vendor Advisory
- http://www.securityfocus.com/bid/25218Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35825
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.