4.3
CVE-2007-3067
- EPSS 1.07%
- Veröffentlicht 06.06.2007 01:30:00
- Zuletzt bearbeitet 16.06.2026 22:41:00
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in the Attunement and Key Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the (1) keyshow, (2) sortkey, and (3) show parameters to index.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eqdkp ≫ Attunement And Key Version <= 0.95
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.07% | 0.603 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://osvdb.org/36930
http://secunia.com/advisories/25538
http://sourceforge.net/project/shownotes.php?release_id=512860&group_id=167016
http://www.vupen.com/english/advisories/2007/2045
https://exchange.xforce.ibmcloud.com/vulnerabilities/34700