4.3

CVE-2007-2337

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS 0.96.6 Alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (b) magpie_simple.php in external/magpierss/scripts/, the (2) rss_url parameter to (c) magpie_slashbox.php in external/magpierss/scripts/, and the (3) body parameter to the (d) weblogmodule (aka Weblog Comments) module.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OicgroupExponent Cms Updatealpha Version <= 0.96.6
OicgroupExponent Cms Version0.94
OicgroupExponent Cms Version0.95
OicgroupExponent Cms Version0.96.1
OicgroupExponent Cms Version0.96.3
OicgroupExponent Cms Version0.96.4
OicgroupExponent Cms Version0.96.5 Updaterc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.82% 0.76
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://www.bugtraq.ir/articles/advisory/exponent_multiple_vulnerabilities/10
http://www.securityfocus.com/bid/23574
Exploit
http://osvdb.org/35640
http://osvdb.org/35641
http://osvdb.org/35642
http://osvdb.org/35643
https://exchange.xforce.ibmcloud.com/vulnerabilities/34077