VulnerabilityModified
CVE-2007-4297
Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp in Dersimiz Haber Ekleme Modulu allow remote attackers to inject arbitrary web script or HTML via the (1) yazan, (2) mail, and (3) yorum parameters.
MEDIUM 4.3EPSS 1.22%
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp in Dersimiz Haber Ekleme Modulu allow remote attackers to inject arbitrary web script or HTML via the (1) yazan, (2) mail, and (3) yorum parameters. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- aspindir/dersimiz haber ekleme modulu
- Source
- cve@mitre.org
References
- http://osvdb.org/37537
- http://secunia.com/advisories/26380Vendor Advisory
- http://www.packetstormsecurity.org/0708-exploits/dersimiz-xss.txt
- http://www.securityfocus.com/bid/25250
- http://www.vupen.com/english/advisories/2007/2831
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35911
- http://osvdb.org/37537
- http://secunia.com/advisories/26380Vendor Advisory
- http://www.packetstormsecurity.org/0708-exploits/dersimiz-xss.txt
- http://www.securityfocus.com/bid/25250
- http://www.vupen.com/english/advisories/2007/2831
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35911
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.