VulnerabilityModified
CVE-2007-4331
PHP remote file inclusion vulnerability in index.php in FindNix allows remote attackers to include the contents of arbitrary URLs and conduct cross-site scripting (XSS) attacks via a URL in the page parameter.
MEDIUM 4.3EPSS 1.20%
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
PHP remote file inclusion vulnerability in index.php in FindNix allows remote attackers to include the contents of arbitrary URLs and conduct cross-site scripting (XSS) attacks via a URL in the page parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- ctw design/findnix
- Source
- cve@mitre.org
References
- http://osvdb.org/38709
- http://securityreason.com/securityalert/2992
- http://www.securityfocus.com/archive/1/475962/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35920
- http://osvdb.org/38709
- http://securityreason.com/securityalert/2992
- http://www.securityfocus.com/archive/1/475962/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35920
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.