VulnerabilityModified
CVE-2007-6270
Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2) template parameter to pages/default.aspx.
MEDIUM 4.3EPSS 2.33%
Does this matter?
Lower severity and a low EPSS score (2.33%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2) template parameter to pages/default.aspx.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.33% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- xigla/absolute news manager.net
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=119678724111351&w=2
- http://osvdb.org/40577
- http://osvdb.org/40578
- http://secunia.com/advisories/27923Vendor Advisory
- http://www.procheckup.com/Vulnerability_PR07-39.php
- http://www.securityfocus.com/bid/26692Exploit, Patch
- http://www.xigla.com/news/default.aspx
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38872
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38873
- http://marc.info/?l=bugtraq&m=119678724111351&w=2
- http://osvdb.org/40577
- http://osvdb.org/40578
- http://secunia.com/advisories/27923Vendor Advisory
- http://www.procheckup.com/Vulnerability_PR07-39.php
- http://www.securityfocus.com/bid/26692Exploit, Patch
- http://www.xigla.com/news/default.aspx
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38872
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38873
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.