VulnerabilityModified
CVE-2007-4434
Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the Text File Search ASP (Classic) edition allows remote attackers to inject arbitrary web script or HTML via the query parameter.
MEDIUM 4.3EPSS 1.52%
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the Text File Search ASP (Classic) edition allows remote attackers to inject arbitrary web script or HTML via the query parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- aspindir/text file search
- Source
- cve@mitre.org
References
- http://osvdb.org/37733
- http://securityreason.com/securityalert/3046
- http://www.packetstormsecurity.org/0708-exploits/tfsc-xss.txt
- http://www.securityfocus.com/bid/25350Exploit
- http://osvdb.org/37733
- http://securityreason.com/securityalert/3046
- http://www.packetstormsecurity.org/0708-exploits/tfsc-xss.txt
- http://www.securityfocus.com/bid/25350Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.