4.3

CVE-2007-2610

Cross-site scripting (XSS) vulnerability in OpenLD before 1.1.9, and 1.1-modified before 1.1-modified3, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the Search feature, possibly the term parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenldOpenld Version <= 1.1.8
OpenldOpenld Version <= 1.1_modified2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.665
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/35871
http://secunia.com/advisories/25168
Vendor Advisory
http://sourceforge.net/project/shownotes.php?release_id=507099
Patch
http://www.openld.com/forum/viewtopic.php?id=216
Patch
URL Repurposed
http://www.openld.com/forum/viewtopic.php?id=217
Patch
URL Repurposed
http://www.securityfocus.com/bid/23896
Patch
http://www.vupen.com/english/advisories/2007/1730
https://exchange.xforce.ibmcloud.com/vulnerabilities/34198