4.3

CVE-2007-1848

Exploit
Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php in Drake CMS allows remote attackers to inject arbitrary web script or HTML via the desc[][title] field.  NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drake TeamDrake Cms Version0.3.7
Drake TeamDrake Cms Version0.3.7_beta
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.09% 0.61
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://securityreason.com/securityalert/2522
http://www.securityfocus.com/archive/1/464272/100/0/threaded
http://www.securityfocus.com/bid/23216
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/33332